How we protect your data.
Encryption at rest and in transit
All data encrypted at rest using AES-256. All data in transit encrypted using TLS 1.3. Encryption keys managed via AWS KMS with hardware security modules.
UK data residency
All customer data stored in AWS eu-west-2 (London). No data leaves the United Kingdom. Relevant for UK GDPR compliance and data sovereignty requirements.
Role-based access control
Granular permissions by role: planners, field operatives, operations directors, finance. Field Operatives see only their own jobs. Managers see their teams. Admins control everything.
Single sign-on (SSO)
SAML 2.0 and OAuth 2.0 SSO support. Integrate with your existing identity provider: Azure AD, Google Workspace, Okta. MFA enforced for all administrator accounts.
Full audit logging
Every user action is logged, including job creation, schedule changes, compliance captures and invoice approvals, with timestamp, user ID and IP address. Audit logs are immutable and retained for seven years.
Penetration testing
Annual third-party penetration testing by CREST-certified security firm. Test reports available to enterprise customers under NDA on request.
Automated backups
Database backups every 6 hours. Point-in-time recovery to any 5-minute interval within the last 35 days. Backups stored in a separate AWS region and tested quarterly.
Uptime and SLA
99.9% uptime SLA for Professional and AI+ plans. Status page at status.clockworkit.co.uk. Planned maintenance windows communicated 7 days in advance.
Data protection. Documented.
TotalCtrl is operated by Clockwork IT Ltd, registered as a Data Controller with the Information Commissioner’s Office (ICO). Our data processing practices comply with UK GDPR.
Data Controller registration
Clockwork IT Ltd is registered with the ICO. Registration number available on request.
Data Processing Agreements
DPAs available for enterprise customers and public sector organisations. Contact us with your requirements.
Subject access requests
We respond to all data subject requests within 30 days. Contact info@clockworkit.co.uk.
Data retention
Customer data retained for the duration of the contract plus 7 years for audit purposes. Deletion on request after contract end.
Aligned, not certified.
We do not yet hold formal ISO 27001, SOC 2 or Cyber Essentials Plus certifications. What we do is operate to the practices those frameworks describe. Formal certification is on our roadmap for 2026 or 2027.
Enterprise procurement teams that require a certified supplier can talk to us about scope and timeline. Everyone else gets the security posture below today.
ISO 27001 controls
Our information security management practices are aligned with the ISO 27001 controls framework. Access control, incident response, supplier management and continuous improvement follow the standard.
Cyber Essentials guidance
Infrastructure hardened per the UK NCSC Cyber Essentials scheme. Boundary firewalls, secure configuration, access control, malware protection and patch management all in place.
UK GDPR
Fully compliant as a UK-registered data controller with the ICO. Not a framework we align to, a legal obligation we meet.
CREST penetration testing
Annual third-party penetration testing carried out by a CREST-certified security firm. Test summaries available under NDA.