Security first
Security shapes every recommendation we make, including the ones about AI and everyday IT.
You trust a security partner with monitoring access, sensitive information, compliance evidence and business continuity. This page tells you who we are, how we deliver the service and how we protect your information.
Who we are
Elmfort is a cybersecurity and operational resilience specialist. We also help organisations adopt AI responsibly. For many IT providers, security is an add-on to IT support. For us, cybersecurity and resilience are the primary products.
Our service is designed for UK organisations with fewer than 250 employees, particularly in financial services, professional services and B2B technology. These organisations have sensitive data, compliance obligations and critical technology dependencies that need robust management.
How we work
You get enterprise-level expertise with the clarity and accessibility of a smaller professional-services firm. You know who to call, and that person knows your organisation.
Security shapes every recommendation we make, including the ones about AI and everyday IT.
We look for risks before they become incidents, and we follow each fix through to verification.
We explain risks and decisions in plain English. Technical detail is there when you want it.
We do what we agree, when we agree it, and we keep the evidence to show it.
We turn security requirements into managed routines, so that audits stop being projects.
Our delivery model
Elmfort is accountable for your service. We combine established security platforms, a contracted security operations partner and specialist security and resilience professionals. Elmfort governs all of them centrally.
You buy one integrated Elmfort service. You do not need separate subscriptions for the tools underneath it.
Security and privacy practices
Our service needs privileged access and sensitive evidence. We apply the same controls to ourselves that we recommend to you.
When the SOC confirms a threat, it escalates to Elmfort and to the contacts you nominate. We coordinate the response, track the incident to resolution and report what happened and what changed.
Your service agreement sets the containment actions that the SOC can take, the escalation contacts and the response times. If you need guaranteed specialist mobilisation, we offer enhanced incident response retainers.
See our incident workflowTransparency
Security marketing often overpromises. We would rather tell you exactly what our contracts deliver.
Trust Centre
Our cover is provided by Hiscox. Download the current certificates for your supplier records. Your contract and our insurance are both with Hexlium Ltd.
Covers claims that arise from our professional advice and services.
Covers cyber and data incidents that affect our own business.
The UK government-backed cyber security certification, with independent technical testing.
A UK cyber security standard for small and medium-sized organisations, aligned to ISO 27001.
The international standard for information security management.
The international code of practice for information security in cloud services.
The international standard for privacy information management.
The international standard for business continuity management.
The international standard for IT service management.
The international standard for managing AI systems responsibly.
The international standard for quality management.
Assurance from the UK's National Cyber Security Centre that a provider meets its standard for delivering a cyber security service.
The NCSC-assured scheme for organisations that give small and medium-sized businesses trusted cyber security advice.
Send us your supplier security questionnaire, or ask for our data processing agreement and list of subprocessors. We'll respond with what your process needs.