Trust at BuiltByGo
Last reviewed: 3 May 2026
A single point of reference for procurement, legal, and risk teams evaluating BuiltByGo Ltd. Everything in one place — no hunting through legal pages.
If you can't find what you're looking for here, contact legal@builtbygo.com or procurement@builtbygo.com.
At a glance
| Company | BuiltByGo Ltd · Established December 2017 |
| Registered | England and Wales · Company No. 11121829 |
| ICO Registration | ZA564668 |
| Registered Office | The Mill House Court Farm, Church Lane, Norton, Worcester, WR5 2PS |
| Director | James Recker (Founder) |
| Sector | Institutional digital platforms, applications, hosting, support |
| Insurance | £2m PI · £2m PL · £1m Cyber · £10m EL |
| Compliance posture | UK GDPR · ISO/IEC 27001 aligned · NIST CSF aligned |
| In active pursuit | Cyber Essentials Plus (target completion 2026) |
| On 2026–2027 roadmap | ISO/IEC 27001 certification |
Trust documentation
Security and operations
- Security & Trust — information security framework, infrastructure controls, encryption, access management, backup and DR, incident response
- Sub-processors register — every third-party service that may process client data, with regions and transfer mechanisms
- AI Usage Policy — operational rules for AI tooling, named tools, anonymisation policy, conditional sub-processor framing
- Vulnerability Disclosure Policy — how to report security issues, response timelines, safe harbour terms
- /.well-known/security.txt — RFC 9116 machine-readable disclosure point
Privacy and data protection
- Privacy Policy — how we handle personal data on this website and in pre-engagement enquiries (UK GDPR compliant)
- Data Processing Agreement (DPA) — Article 28 compliant DPA for client engagements; covers UK GDPR, EU GDPR, Brazilian LGPD, Mexican LFPDPPP
- Cookie Policy — our cookie usage and your choices
Governance and ethics
- Code of Conduct — ethics, anti-bribery, whistleblowing, supplier expectations, DEI
- Modern Slavery Statement — voluntary statement (below the £36m threshold) covering business and supply chain
- Accessibility Statement — WCAG 2.2 AA conformance commitment
- Terms of Service — website use terms
Procurement enablement
- Procurement FAQ — answers to the questions procurement teams typically ask, in advance
Frameworks and standards
Currently aligned
- ISO/IEC 27001 control families
- NIST Cybersecurity Framework (CSF)
- UK GDPR and DPA 2018
- WCAG 2.2 Level AA (web accessibility)
- PECR (Privacy and Electronic Communications Regulations)
- UK Bribery Act 2010
- Modern Slavery Act 2015 (voluntary statement)
- Equality Act 2010
Currently being pursued
- Cyber Essentials Plus — accreditation in active pursuit, target completion through 2026
On the roadmap
- ISO/IEC 27001 — formal certification, 2026–2027
Sub-processors
Our sub-processor register is published in full at builtbygo.com/subprocessors.
Active sub-processors: Cloudflare · Railway · Supabase · Sanity · Resend · PostHog · Sentry · Better Uptime · DeepL (conditional)
Conditional AI sub-processors (governed by AI Usage Policy): Anthropic (Claude under Commercial Terms with DPA in place) · DeepSeek
We notify clients 30 days before adding any new sub-processor, with a 14-day objection window.
Insurance
Certificates available on execution of NDA or MSA.
| Cover | Limit |
|---|---|
| Professional Indemnity | £2,000,000 |
| Public Liability | £2,000,000 |
| Cyber Liability | £1,000,000 |
| Employer's Liability | £10,000,000 |
Contact legal@builtbygo.com to request certificates.
Standard contracts
The following contractual templates are maintained for institutional engagements and available to clients:
| Document | Purpose |
|---|---|
| Master Services Agreement (MSA) | Institutional project engagements — client-owns-IP, fixed-fee, full liability and acceptance criteria framework |
| Statement of Work (SoW) | Per-engagement scope, deliverables, timetable, charges |
| Data Processing Agreement (DPA) | Article 28 compliant, public version at /dpa |
| Mutual NDA | Pre-engagement confidentiality |
Templates available on request via legal@builtbygo.com.
Security questionnaires
We complete standard security questionnaires for institutional procurement, including:
- CAIQ (Consensus Assessments Initiative Questionnaire)
- SIG / SIG Lite (Standardized Information Gathering)
- ISO 27001-aligned custom client questionnaires
- Client-specific procurement forms
Typical turnaround: 5–10 working days. Most standard items are pre-answered through our published Security & Trust, DPA, and Sub-processors register.
Audit and inspection
Under our DPA, clients may audit our compliance through:
- Documentation review — certifications, security questionnaire responses, sub-processor register
- Standard questionnaires — CAIQ, SIG, or client custom forms
- Independent third-party audit — with 30 days' notice, during business hours, by mutually agreed auditor
See DPA Section 11 for the full audit framework.
Incident response
| Breach notification | Without undue delay; in any event within 72 hours of awareness (UK GDPR Article 33) |
| P1 incident post-mortem | Within 10 Business Days of resolution |
| Status page | status.builtbygo.com (forthcoming) |
| Vulnerability reports | security@builtbygo.com — see VDP |
Contact directory
For institutional clients: please use the dedicated channel where possible — it routes to the right person faster.
| Topic | Contact |
|---|---|
| Procurement and vendor onboarding | procurement@builtbygo.com |
| Privacy, data protection, DSARs, sub-processor questions | privacy@builtbygo.com |
| Security, vulnerability reports, security questionnaires | security@builtbygo.com |
| Legal, contracts, NDA, insurance certificates | legal@builtbygo.com |
| Accessibility queries | accessibility@builtbygo.com |
| Whistleblowing reports | whistleblowing@builtbygo.com |
| General enquiries | hello@builtbygo.com |
| Address | The Mill House Court Farm, Church Lane, Norton, Worcester, WR5 2PS, United Kingdom |
Document history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 3 May 2026 | Initial publication. Consolidates trust documentation into a single landing page for institutional buyers. |