Due diligence
The vendor due diligence pack.
Everything an IT, security, or procurement reviewer normally asks us for, in one place. Current versions, no email required. If your questionnaire needs something that is not here, ask and we will answer it directly.
Documents
- Security overview (PDF)
Architecture, data handled, access control, encryption, application security, monitoring, incident response, retention, and our certification position. Offered in lieu of an ISO 27001 certificate. - Data protection impact assessment (PDF)
A voluntary DPIA for the TPS/CTPS screening processing: what is processed, necessity and proportionality, risks, and mitigations. - Acceptable use policy (PDF)
The rules that bind anyone with access to TPSClear systems, including how AI tooling may and may not be used. - Secure development standard (PDF)
OWASP-aligned development practice: input handling, secrets, least privilege, dependency gates, and fail-closed design.
Published policies
- Sub-processor list: every third party that touches service data, and what for.
- Privacy policy: how we handle personal data, as controller and as processor.
- Terms of service: the agreement the service runs on.
Available on request
A signed Data Processing Agreement (included on the Scale plan and above, available to any plan on request), plus our fraud risk and modern slavery risk assessments. Ask us and we will send the current versions.
Who this is for. These documents are written for vendor onboarding and security review. If you are evaluating the product itself, start with how it works or pricing.