Due diligence

The vendor due diligence pack.

Everything an IT, security, or procurement reviewer normally asks us for, in one place. Current versions, no email required. If your questionnaire needs something that is not here, ask and we will answer it directly.

Documents

  • Security overview (PDF)
    Architecture, data handled, access control, encryption, application security, monitoring, incident response, retention, and our certification position. Offered in lieu of an ISO 27001 certificate.
  • Data protection impact assessment (PDF)
    A voluntary DPIA for the TPS/CTPS screening processing: what is processed, necessity and proportionality, risks, and mitigations.
  • Acceptable use policy (PDF)
    The rules that bind anyone with access to TPSClear systems, including how AI tooling may and may not be used.
  • Secure development standard (PDF)
    OWASP-aligned development practice: input handling, secrets, least privilege, dependency gates, and fail-closed design.

Published policies

Available on request

A signed Data Processing Agreement (included on the Scale plan and above, available to any plan on request), plus our fraud risk and modern slavery risk assessments. Ask us and we will send the current versions.

Who this is for. These documents are written for vendor onboarding and security review. If you are evaluating the product itself, start with how it works or pricing.