About In4ra
Transparency is at the heart of how we operate. This page sets out our certifications, compliance posture, security practices and the policies that govern how we work.
We hold and maintain the certifications that matter most to our clients.
In4ra holds Cyber Essentials certification, demonstrating that our systems meet the UK government's baseline cyber security standard. This covers firewalls, secure configuration, access control, malware protection and patch management.
We align with the Department for Education's cyber security standards for schools and colleges, helping education clients meet their statutory obligations around data protection and network security.
We process and handle client data in accordance with UK GDPR and the Data Protection Act 2018. Our data processing agreements are available on request for all managed service clients.
How we protect our own systems — and by extension, yours.
All In4ra staff operate on a least-privilege model. Access to client systems is granted only where required and reviewed regularly.
We use endpoint detection and response (EDR) tooling and 24/7 monitoring on our own infrastructure, with the same recommended for all managed clients.
Operating systems and third-party software are patched on a regular cycle. Critical patches are applied within 14 days of release.
We maintain a documented incident response plan. In the event of a security incident affecting a client, we follow a structured triage, containment and remediation process.
All In4ra staff complete annual cyber security awareness training and phishing simulation exercises.
We assess the security posture of our key technology suppliers and only partner with vendors who meet our minimum security requirements.
If you believe you have found a security vulnerability in any In4ra system or website, please report it responsibly. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
Report a vulnerability: [email protected]