Trust Centre

Our commitment to information security, data protection, and the controls that protect your organisation.

Our Commitment To Security

PRD Technologies treats information security as fundamental to how we operate. Our Intelligent Billing platform and associated services are protected by a documented Information Security Management System (ISMS) structured on the ISO 27001 framework and independently audited each year. We hold current Cyber Essentials and Cyber Essentials Plus certifications which are independently verified through hands-on technical assessment and our production infrastructure is hosted in the UK on Microsoft Azure.

We are transparent about what this means. Our ISMS is aligned to ISO 27001 and operated to its principles; it is not a formal certification. Where we describe controls in this document, we do so as commitments we can evidence on request.

Independently Certified

Cyber Essentials

UK government-backed • renewed annually • independently verifiable

Cyber Essentials Plus

Hands-on independent technical testing, not self-assessment

We Operate And Align To

ISO 27001-aligned ISMS

Operated & audited to the standard.

UK-hosted on Microsoft Azure

Production data held in the UK region

UK GDPR

Policies & procedures built to our obligations

What We’re Certified Against, And What We Align To

Our certifications are independently verified. Our ISO 27001 position is a declared alignment, operated and audited to the standard.

Cyber Essentials (Certified)

UK government-backed scheme covering five key technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. Renewed annually and independently verifiable via the IASME registry.

Cyber Essentials Plus (Certified)

Enhanced certification requiring independent, hands-on technical verification of the same five controls, not self-assessment, providing higher assurance for clients and procurement teams.

ISO 27001 (Aligned)

We operate a full ISMS policies, risk registers, asset inventories and management-review processes structured on ISO 27001 and audited annually by an independent external assessor. We are clear this reflects alignment, not formal certification

UK GDPR (Observed)

Our policies and procedures are designed to meet our obligations under UK GDPR, including data-subject rights, privacy notices, records of processing activities (RoPA), and breach response.

Microsoft Azure (Inherited assurance)

Our services run on Microsoft Azure, which maintains an extensive portfolio of independent certifications including ISO 27001 and SOC 2. This provides foundational infrastructure assurance beneath our own controls.

How We Protect Your Information

Our controls span technical, organisational and human layers, operated to ISO 27001 principles and reviewed regularly through independent assessment.

Information Security Management System

A documented ISMS covering policies, risk management, asset inventory and management-review cycles, structured on ISO 27001 and audited annually, giving clients and partners confidence in how we manage and protect their information.

Leadership & governance

Security is a standing leadership-level agenda item, with defined ownership and accountability. Management reviews assess performance, risk exposure and continuous improvement.

Access control

Access is granted on a least-privilege basis, tied to defined roles and business need. Multi-factor authentication is enforced across staff access; privileged access is further restricted. User access is reviewed regularly and revoked promptly on departure or role change.

Data protection & privacy

Client data is processed only as necessary and in line with agreed terms and UK GDPR. Data is encrypted at rest and in transit. We maintain records of processing activities (RoPA), conduct DPIAs where required, publish a privacy notice, and support data-subject rights (access, correction, erasure). We do not sell personal data.

Infrastructure & cloud security

Production systems are hosted in the UK on Microsoft Azure, with enterprise-grade physical and logical controls. We apply network segmentation, firewalling, encrypted connections (TLS 1.2+) and endpoint protection, and the Azure shared-responsibility model is documented and understood.

Vulnerability, patching & security testing

We run a structured vulnerability-management process using automated scanning and threat intelligence, with risk-rated remediation to priority timelines and consistent patching across operating systems, applications and third-party components. We commission independent penetration testing periodically, with findings tracked to closure.

Business continuity & backups

We maintain a Business Continuity Plan covering critical systems and services. Backups are performed, tested and stored securely, recovery objectives are defined for key services, and plans are reviewed and tested at least annually.

Incident management

We operate a documented incident-response plan covering detection, containment, investigation, notification and recovery. Incidents are logged, tracked and reviewed to drive improvement. In the event of a breach affecting client data, we are committed to timely, transparent notification in line with our contractual and regulatory obligations.

People security

Pre-employment screening is carried out appropriate to role and data access. Staff receive clear security responsibilities at onboarding and complete monthly ongoing security-awareness training, with completion tracked and recorded; role-specific training is provided for staff with elevated access. Access is revoked promptly on leaving, and disciplinary procedures address policy violations.

Supplier & third-party risk

Suppliers with access to our systems or client data are subject to due diligence before onboarding, and contracts include data-processing and security obligations aligned to UK GDPR. Key suppliers, including cloud and security partners, are reviewed periodically. Our sub-processor list is available on request.

Where Your Data Lives

Your data stays in the UK. Our production infrastructure is hosted in Microsoft Azure’s UK region. Client data is processed and stored in the UK, supporting UK GDPR obligations and data-residency requirements that matter to UK and public-sector clients.

Working With Us

Questions about our security?

We welcome security enquiries from prospective and existing clients. We are happy to discuss our posture, complete supplier due-diligence questionnaires, and share supporting documentation including ISMS policy summaries and independent audit and testing summaries, under NDA.

Responsible disclosure: security researchers can report a suspected vulnerability to [email protected]. Please allow us reasonable time to investigate and remediate before any public disclosure.

[email protected]          IntelligentBilling.com

PRD Technologies Ltd  |  Intelligent Billing  |  Trust Centre

Last updated: July 2026. Reviewed at least annually and updated promptly following any significant change to our security posture, certifications or practices.

Our ISO 27001 position reflects alignment with the standard, operated and audited to its principles. It is not a formal certification.

Awards

Winner of Software Vendor of the Year CRN Channel Awards 2022, 2023 & 2024

Winner of Billing Platform Vendor 2023 & 2024 Services to the Channel Award 2023 – Comms Business Awards

Winner of Software Product of the Year Print IT Awards 2024

Winner of Software Product of the Year Technology Reseller Awards 2022

About Us

Intelligent Billing is the multi-award winning range of software from PRD Technologies Ltd, delivering innovative billing solutions.

Business Info

Belvedere House, Basing View, Basingstoke RG21 4HG

01256 806 832

[email protected]

Intelligent Billing

Benefits & Features

Automated Billing Software

Billing API

Analytics

Sectors We Serve

Policies

Privacy Policy

Cookie Policy

Trust centre

LinkedIn

YouTube

PRD Technologies Ltd, Registered Number: 5993489 | © 2026 PRD Technologies Ltd.