Information Security

Immigration casework involves sensitive personal information. This page sets out our approach to keeping it secure.

Access Controls and Authentication

Access to client systems and case files is restricted to staff who need it, using individual logins and authentication controls rather than shared credentials.

Secure Devices and Email

Staff use secured devices and business email systems for client communication and document handling, rather than personal or unsecured accounts.

Cloud Services and Data Storage

Client data is stored in managed cloud case-management and document systems, chosen with appropriate security and access controls, rather than on unmanaged local storage.

Remote Working

Remote and hybrid working is supported through the same secured systems and access controls used in our offices, consistent with our Business Continuity approach.

Confidential Information and Backups

Confidential client information is handled in line with our Data Protection policy, and systems are backed up to protect against data loss.

Third-Party Technology and Incidents

We assess the security standards of third-party technology providers before adopting them, and we have an internal process for responding to a suspected cyber incident, including containment and, where required, notification.

A Note on Certifications

We do not claim Cyber Essentials or ISO 27001 certification unless and until we hold it. This page describes our practical security measures rather than a certified standard.

Staff Responsibilities

All staff are responsible for following this policy, including safeguarding their own login credentials and reporting any suspected security concern promptly.

Related Information

Request Information Security Information

For a specific information-security question as part of a tender or due-diligence process, contact our team directly.

Reviewed by the Morgan Smith Immigration team — IAA-regulated UK immigration specialists. Last reviewed 2026-09-23.

Scroll to Top