Multi-factor authentication
Mandatory for all staff accessing production systems and customer data
Trust Centre
Upstream BPO operates an information security management system certified to ISO/IEC 27001:2022. This page states the controls we run: role-based access with least privilege, mandatory multi-factor authentication, semi-annual access reviews and 24/7 monitoring.
These points summarise the public scope of this page and the main contact or review context around it.
Multi-factor authentication
Mandatory for all staff accessing production systems and customer data
Access reviews
Conducted semi-annually
Monitoring
24/7 SIEM with SOC monitoring
Certified ISMS
ISO/IEC 27001:2022, Certificate II-23080301
Section 1
Our controls sit inside an information security management system certified to ISO/IEC 27001:2022 under Certificate II-23080301, governed by Statement of Applicability SOA-UBSB-01 dated 12 February 2023. The sections below follow the Annex A control themes of the 2022 standard: organizational controls (A.5), people controls (A.6) and technological controls (A.8).
Certificate details, certified scope, penetration testing cadence and our vulnerability disclosure programme are stated on our security posture page.
Section 2
Upstream BPO enforces role-based access control with least privilege across all systems that process customer data. Access is granted against a defined role rather than per individual request, and each role carries the minimum permissions the work requires.
We support SSO and SAML for enterprise customer integrations, so that customers govern authentication to their own systems through their existing identity provider.
We review access rights semi-annually. Each review confirms that granted access still matches the role and removes access that is no longer required.
Section 3
Multi-factor authentication is mandatory for all Upstream BPO staff accessing production systems and customer data. It is not optional, not role-dependent and not limited to administrative accounts.
Section 4
Upstream BPO operates 24/7 Security Information and Event Management with SOC monitoring. Coverage is continuous rather than limited to business hours.
Where monitoring identifies a confirmed incident, it moves into the incident response process, which carries its own severity classification, on-call coverage and notification commitments.
Section 5
Upstream BPO completes employee background checks before hire. Screening is completed as a condition of employment rather than after a start date.
Security awareness training is mandatory and runs annually for all staff.
Section 6
Upstream BPO runs endpoint detection and response tooling across staff devices. Devices used to access production systems and customer data carry that tooling as a condition of access.
Section 7
Change management is part of our certified scope and corresponds to ISO/IEC 27001:2022 Annex A control A.8.32. Changes to systems that process customer data follow the documented change process rather than being applied ad hoc.
Section 8
Cryptographic standards are stated on our data privacy page: data in transit is protected by TLS 1.2 or later using the AES-256 cipher suite, and data at rest is encrypted with AES-256.
Penetration testing cadence and our coordinated vulnerability disclosure programme, including acknowledgement and disclosure timelines, are stated on our security posture page.
Answers are stated in full here so they are quotable directly into a security questionnaire.
Yes. Multi-factor authentication is mandatory for all Upstream BPO staff accessing production systems and customer data.
Yes. Upstream BPO supports SSO and SAML for enterprise customer integrations.
Semi-annually. Each review confirms that granted access still matches the role and removes access that is no longer required.
Yes. Upstream BPO operates 24/7 Security Information and Event Management with SOC monitoring.
Yes. Employee background checks are completed before hire, as a condition of employment. Security awareness training is mandatory and runs annually.
ISO/IEC 27001:2022, under Certificate II-23080301, governed by Statement of Applicability SOA-UBSB-01 dated 12 February 2023.
Use the connected pages below for deeper privacy, governance, service or contact context.
Security Posture
Certificate details, certified scope, penetration testing and vulnerability disclosure.
Open page
Data Privacy
Cryptographic standards, data subject rights and residency.
Open page
Incident Response
Severity classification, on-call coverage and breach notification.
Open page
Security & Trust Contact
Reach the data protection officer and the single trust inbox.
Open page
Contact & Escalation
Security questionnaires, control mapping requests and Statement of Applicability requests route to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.
Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.
Your choice about cookies
We use essential cookies to run this site. With your permission we would also use functional, performance, analytics and marketing cookies. Nothing optional loads until you choose.