Serious about security. Easy to work with.

You trust a security partner with monitoring access, sensitive information, compliance evidence and business continuity. This page tells you who we are, how we deliver the service and how we protect your information.

Who we are

A specialist, not a traditional MSP.

Elmfort is a cybersecurity and operational resilience specialist. We also help organisations adopt AI responsibly. For many IT providers, security is an add-on to IT support. For us, cybersecurity and resilience are the primary products.

Our service is designed for UK organisations with fewer than 250 employees, particularly in financial services, professional services and B2B technology. These organisations have sensitive data, compliance obligations and critical technology dependencies that need robust management.

Trading name
Elmfort
Legal entity
Hexlium Ltd, registered in England and Wales
Company number
14408745
Registered office
86-90 Paul Street, London, EC2A 4NE, United Kingdom

How we work

Enterprise-grade security, with personal attention.

You get enterprise-level expertise with the clarity and accessibility of a smaller professional-services firm. You know who to call, and that person knows your organisation.

Security first

Security shapes every recommendation we make, including the ones about AI and everyday IT.

Proactive service

We look for risks before they become incidents, and we follow each fix through to verification.

Clear communication

We explain risks and decisions in plain English. Technical detail is there when you want it.

Reliability

We do what we agree, when we agree it, and we keep the evidence to show it.

Compliance made simple

We turn security requirements into managed routines, so that audits stop being projects.

Our delivery model

Specialist platforms and partners, governed by Elmfort.

Elmfort is accountable for your service. We combine established security platforms, a contracted security operations partner and specialist security and resilience professionals. Elmfort governs all of them centrally.

You buy one integrated Elmfort service. You do not need separate subscriptions for the tools underneath it.

Elmfort
Service ownership, risk management, governance, remediation coordination, reporting and security leadership
Security operations partner
24/7 monitoring, investigation and agreed containment actions
Specialist professionals
Security engineering, compliance and resilience work under Elmfort's direction
Security platforms
Detection, vulnerability management and governance platforms, licensed through your subscription
See who does what

Security and privacy practices

How we protect your information.

Our service needs privileged access and sensitive evidence. We apply the same controls to ourselves that we recommend to you.

Data handling

  • We ask only for the access that the agreed security coverage needs, and we review it regularly.
  • We protect access to customer systems with multi-factor authentication and least-privilege permissions.
  • Each customer contract includes a data processing agreement.
  • We manage subprocessors under written agreements, and we tell you who they are.
  • We apply appropriate safeguards when customer data crosses supplier or national boundaries.
  • We do not ask you to send sensitive infrastructure details or security configurations through public forms.
Read our privacy policy

Incident escalation

When the SOC confirms a threat, it escalates to Elmfort and to the contacts you nominate. We coordinate the response, track the incident to resolution and report what happened and what changed.

Your service agreement sets the containment actions that the SOC can take, the escalation contacts and the response times. If you need guaranteed specialist mobilisation, we offer enhanced incident response retainers.

See our incident workflow

Transparency

What we promise, and what we don't.

Security marketing often overpromises. We would rather tell you exactly what our contracts deliver.

  • We use a contracted security operations partner for 24/7 monitoring.
  • We prepare you for Cyber Essentials and ISO 27001. The certification body makes the certification decision.
  • We test recovery arrangements. We do not promise recovery under every possible failure scenario.
  • We document what each system's monitoring can and cannot see, and we record the gaps.
  • We only publish certifications, partnerships and customer outcomes that we can verify.

Trust Centre

Evidence for your due diligence.

Our cover is provided by Hiscox. Download the current certificates for your supplier records. Your contract and our insurance are both with Hexlium Ltd.

Current

Professional indemnity insurance

Covers claims that arise from our professional advice and services.

Level of cover
£1,000,000
Insurer
Hiscox Insurance Company Limited
Period
1 September 2026 to 31 August 2027
Policy number
PL-PSC10003758426/01
Download certificate (PDF)
Current

Cyber and data insurance

Covers cyber and data incidents that affect our own business.

Level of cover
£1,000,000
Insurer
Hiscox Insurance Company Limited
Period
1 September 2026 to 31 August 2027
Policy number
PL-PSC10003758426/01
Download certificate (PDF)

Certifications

In progress

Cyber Essentials Plus

The UK government-backed cyber security certification, with independent technical testing.

In progress

IASME Cyber Assurance

A UK cyber security standard for small and medium-sized organisations, aligned to ISO 27001.

In progress

ISO/IEC 27001

The international standard for information security management.

In progress

ISO/IEC 27017

The international code of practice for information security in cloud services.

In progress

ISO/IEC 27701

The international standard for privacy information management.

In progress

ISO 22301

The international standard for business continuity management.

In progress

ISO/IEC 20000-1

The international standard for IT service management.

In progress

ISO/IEC 42001

The international standard for managing AI systems responsibly.

In progress

ISO 9001

The international standard for quality management.

NCSC assurance

In progress

NCSC Assured Service Provider

Assurance from the UK's National Cyber Security Centre that a provider meets its standard for delivering a cyber security service.

In progress

NCSC Cyber Advisor

The NCSC-assured scheme for organisations that give small and medium-sized businesses trusted cyber security advice.

Doing supplier due diligence on us?

Send us your supplier security questionnaire, or ask for our data processing agreement and list of subprocessors. We'll respond with what your process needs.