Skip to main content

Security and confidentiality

Your records are our obligation while we hold them

Records are tracked at box and file level from collection to return, handled by named teams under individual confidentiality agreements, processed in access-controlled areas, and delivered over encrypted channels. Where documents cannot leave your building, we scan on your premises instead. Nothing is destroyed without your written instruction.

Gloved hands fitting a numbered security seal to a lidded archive container, with a barcode label and a manifest on a clipboard alongside

Almost every archive contains something that would be damaging to lose or to leak. Personnel files, patient records, signed contracts, title deeds, board papers. Handing that to a third party is a genuine risk, and the honest way to address it is to describe the controls rather than display a badge.

Chain of custody

Custody is recorded from the moment records leave your control. A manifest is built with your team before collection, containers are sealed and labelled in front of you, and transport is tracked. On arrival the manifest is reconciled against what physically turned up, and any discrepancy is raised the same day rather than discovered at the end of the project.

  • Box and file level recording, not just a pallet count
  • Sealed, numbered containers with a signed handover
  • Reconciliation on receipt, with same-day exception reporting
  • A documented route for recalling a specific file mid-project
  • A closing reconciliation of everything collected against everything returned

People

Most information loss is not a technical breach. It is a person with more access than they needed. Project teams are named and briefed, work under individual confidentiality agreements, and see only the engagement they are assigned to.

  • Named project teams, disclosed to you on request
  • Individual confidentiality agreements, not just a company-level NDA
  • Access limited to the engagement, so operators cannot browse other clients' material
  • Supervised production areas with controlled entry
  • Personal devices and cameras excluded from production floors

Where the work happens

Some records genuinely cannot leave a building, whether for regulatory reasons, contractual ones or because they are in daily use. In those cases we set up scanning inside your premises and nothing moves at all. Many projects split by record class: sensitive material stays on-site, backfile goes off-site where throughput is higher and cost is lower.

Digital handling

  • Encrypted transfer for delivered output, or physical media by arrangement
  • Access-logged delivery, so you can see who retrieved what
  • Working copies removed from our systems once you have accepted delivery
  • Agreed retention and deletion of any residual project data
  • Sample uploads through this website stored outside the public web root

The end of the project

We never destroy anything on our own initiative. Some record classes must be retained in original form regardless of whether a digital copy exists, and that judgement belongs to you and your compliance function. When you do instruct destruction, it is carried out against a written instruction and evidenced with a certificate.

Ask us harder questions

The questions worth asking a digitization provider are mostly uncomfortable ones: who exactly touches the documents, whether any part of the work is subcontracted, where data physically resides, and what happens on the day something goes wrong. We have written those out in full, including the ones that are awkward for us, because a provider unwilling to answer them is itself the answer.

Frequently asked questions

Do you subcontract any part of the work?

Ask this of any provider, including us, and get the answer in writing. Where any element of a project would involve a third party, that is disclosed before contract rather than discovered afterwards. Undisclosed subcontracting is one of the most common gaps between what a client believes they bought and what actually happens.

Can our records stay inside our building?

Yes. On-site scanning is set up in a room you provide, with our equipment and team working under your access rules. Nothing leaves the premises. It is slower and generally more expensive per page than off-site work, which is why many projects split, keeping only genuinely restricted material on-site.

Are you certified to a named security standard?

We do not publish a certification claim on this site. Our parent company describes its processes as aligned to recognised practice, which is not the same as certification. If your procurement requires documented evidence, ask us directly and we will tell you exactly what can and cannot be evidenced.

Where is our data physically stored?

Storage location is agreed before a project starts, and it matters more than most buyers realise because some organisations have residency obligations. Our group operates a delivery centre in India alongside the UAE facility, so ask specifically where your material will be processed and stored and have the answer written into the contract.

What happens if a document is damaged or lost?

Incidents are reported to you rather than absorbed quietly. Chain-of-custody records identify where an item was last accounted for, which is precisely why they are kept at file rather than box level. Liability and insurance arrangements are set out in the service agreement, and you should read that section carefully.

Who can see our documents during the project?

Only the named team assigned to your engagement. Access is scoped to the project rather than granted broadly across the production floor, operators work under individual confidentiality agreements, and the team can be disclosed to you on request. Personal devices are excluded from production areas.

Have a security requirement to work through?

Send us the constraints. If something cannot be done the way you need it, we would rather say so before a contract than after.

Or call +971 55 430 1681

CallWhatsAppGet Quote