Trust Centre

Information Security

Upstream BPO operates an information security management system certified to ISO/IEC 27001:2022. This page states the controls we run: role-based access with least privilege, mandatory multi-factor authentication, semi-annual access reviews and 24/7 monitoring.

Key information

At-a-glance governance context

These points summarise the public scope of this page and the main contact or review context around it.

Multi-factor authentication

Mandatory for all staff accessing production systems and customer data

Access reviews

Conducted semi-annually

Monitoring

24/7 SIEM with SOC monitoring

Certified ISMS

ISO/IEC 27001:2022, Certificate II-23080301

Section 1

Control environment

Our controls sit inside an information security management system certified to ISO/IEC 27001:2022 under Certificate II-23080301, governed by Statement of Applicability SOA-UBSB-01 dated 12 February 2023. The sections below follow the Annex A control themes of the 2022 standard: organizational controls (A.5), people controls (A.6) and technological controls (A.8).

Certificate details, certified scope, penetration testing cadence and our vulnerability disclosure programme are stated on our security posture page.

Section 2

Access control

Upstream BPO enforces role-based access control with least privilege across all systems that process customer data. Access is granted against a defined role rather than per individual request, and each role carries the minimum permissions the work requires.

We support SSO and SAML for enterprise customer integrations, so that customers govern authentication to their own systems through their existing identity provider.

We review access rights semi-annually. Each review confirms that granted access still matches the role and removes access that is no longer required.

  • Role-based access control (RBAC) with least-privilege enforcement across all systems processing customer data.
  • SSO and SAML supported for enterprise customer integrations.
  • Access reviews conducted semi-annually.

Section 3

Authentication

Multi-factor authentication is mandatory for all Upstream BPO staff accessing production systems and customer data. It is not optional, not role-dependent and not limited to administrative accounts.

Section 4

Monitoring

Upstream BPO operates 24/7 Security Information and Event Management with SOC monitoring. Coverage is continuous rather than limited to business hours.

Where monitoring identifies a confirmed incident, it moves into the incident response process, which carries its own severity classification, on-call coverage and notification commitments.

Section 5

Personnel security

Upstream BPO completes employee background checks before hire. Screening is completed as a condition of employment rather than after a start date.

Security awareness training is mandatory and runs annually for all staff.

  • Employee background checks completed before hire.
  • Annual mandatory security awareness training for all staff.

Section 6

Endpoint protection

Upstream BPO runs endpoint detection and response tooling across staff devices. Devices used to access production systems and customer data carry that tooling as a condition of access.

Section 7

Change management

Change management is part of our certified scope and corresponds to ISO/IEC 27001:2022 Annex A control A.8.32. Changes to systems that process customer data follow the documented change process rather than being applied ad hoc.

Section 8

Encryption and vulnerability management

Cryptographic standards are stated on our data privacy page: data in transit is protected by TLS 1.2 or later using the AES-256 cipher suite, and data at rest is encrypted with AES-256.

Penetration testing cadence and our coordinated vulnerability disclosure programme, including acknowledgement and disclosure timelines, are stated on our security posture page.

Reviewer questions

Questions we are asked in security review

Answers are stated in full here so they are quotable directly into a security questionnaire.

Is multi-factor authentication enforced?

Yes. Multi-factor authentication is mandatory for all Upstream BPO staff accessing production systems and customer data.

Do you support SSO for enterprise customers?

Yes. Upstream BPO supports SSO and SAML for enterprise customer integrations.

How often do you review access rights?

Semi-annually. Each review confirms that granted access still matches the role and removes access that is no longer required.

Do you monitor security events around the clock?

Yes. Upstream BPO operates 24/7 Security Information and Event Management with SOC monitoring.

Do you screen employees before hire?

Yes. Employee background checks are completed before hire, as a condition of employment. Security awareness training is mandatory and runs annually.

Which standard are these controls certified against?

ISO/IEC 27001:2022, under Certificate II-23080301, governed by Statement of Applicability SOA-UBSB-01 dated 12 February 2023.

Contact & Escalation

Security questionnaires, control mapping requests and Statement of Applicability requests route to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.

Next Step

Need a deeper governance review?

Send certificate requests, subprocessor list requests, incident reports and vulnerability disclosures to dpo@upstreambpo.com. We acknowledge security and trust enquiries within 3 business days.