The Raeburn Group · Trust Centre

Security and trust should be verifiable.

This centre publishes the security, privacy, supplier and assurance information that we can support with current evidence. Controls are described conservatively: a control is not presented as operating merely because it is planned, documented or desirable.

Security governance

Group security standards, risk-based control selection, documented ownership and evidence-led assurance across in-scope services.

Identity & access

Least-privilege expectations, account separation, authentication controls and service-specific access restrictions according to the technology in use.

Data protection

UK GDPR-aligned privacy requirements, retention and minimisation principles, supplier review and restricted handling of sensitive information.

Engineering security

Repository-specific linting, type checking, tests, dependency scanning, secret scanning, SAST/CodeQL and production-build verification where those controls are actually configured.

Assurance

Scheduled external checks, retained evidence and conservative assurance statuses. Planned certifications or tests are not represented as completed.

Legal & responsible AI

Published privacy, data-processing, acceptable-use and AI notices set Group expectations for personal data, automation and third-party technology.

Assurance register

What we claim — and what we do not.

Operating controls are limited to what can currently be supported by implementation or retained evidence. Repository-specific controls are not automatically claimed across every Group company.

External assurance automation
Operating
A scheduled GitHub Actions workflow performs external domain checks, scans selected public repositories for likely secret exposure, runs language-native dependency vulnerability audits and retains dated evidence. This is an automated assurance control, not a penetration test or certification.
Dependency vulnerability scanning
Operating
Selected public repositories are audited using npm audit and pip-audit where supported by their dependency files. Results, including non-zero audit outputs, are retained as evidence.
Public-repository secret scanning
Operating
Selected public repositories are scanned for likely secret exposure by a dedicated assurance script. Automated scanning reduces risk but does not guarantee that every secret or credential issue will be detected.
SBOM generation
Implemented in scope
An SBOM workflow exists in this repository. SBOM availability for other Group applications is repository-specific and is not claimed unless generation is actually configured for that project.
Secure build and deployment checks
Repository-specific
Linting, type checking, tests, dependency scanning, SAST/CodeQL and production-build verification are published as controls only for repositories where the relevant workflow or deployment configuration is actually present and operating.
Independent penetration testing
Planned
Independent testing is part of the assurance roadmap. No clean penetration-test claim is made until a genuine report and any required retest evidence exist.
Cyber Essentials
Planned
No Cyber Essentials certification is currently claimed.
ISO/IEC 27001
Planned
No ISO/IEC 27001 certification is currently claimed.

Company coverage

Group standards, entity-specific responsibility.

Each operating company remains responsible for its own services, systems, contracts and personal-data processing. Group standards provide a common baseline but do not imply that every company uses identical technology or controls.

The Raeburn Group

The Raeburn Holding Group Limited

Group governance, shared technology standards and security assurance across Raeburn Group websites and technology projects.

  • Central security standards
  • External assurance automation
  • Supplier and data-protection governance

Raeburn Consulting

The Raeburn Consulting Group

Consulting and AI-enabled transformation services using Group-governed technology and security standards.

  • Secure development expectations
  • Controlled use of AI
  • Customer-data handling requirements

Raeburn Technologies

Raeburn Technologies Limited

Software, platforms, AI systems, data tools and emerging-technology infrastructure.

  • Secure SDLC expectations
  • Environment separation where deployed
  • Secrets and dependency controls

Raeburn Automation Labs

Raeburn Automation Labs Limited

Automation, systems integration and controlled AI/agent development.

  • Permission-scoped integrations
  • Auditability where supported
  • Change and deployment controls

Raeburn Ventures

Raeburn Ventures Limited

Venture building and strategic development of future-facing technology businesses.

  • Security-by-design expectations
  • Supplier and platform review
  • Group security baseline

TRG Recruitment

TRG Recruitment

Recruitment services handling candidate, employer and operational data under Group security and privacy requirements.

  • Input validation where applicable
  • Access-controlled administration
  • Privacy and retention requirements

Raeburn Digital Assets

Raeburn Digital Assets Limited

Digital-asset and infrastructure activity governed by Group security and data-protection standards.

  • Cryptography and key-management expectations
  • Access control
  • Supplier and infrastructure review

Raeburn Welfare Advocates

A trading style of The Raeburn Holding Group Limited

Welfare and life-admin support with a deliberately reduced public-site attack surface and clear service boundaries.

  • Low-complexity public site
  • No public client account system unless separately introduced
  • Sensitive information excluded from public repositories

Caring Crew

Caring Crew

Care, household and learning-support services with security and privacy controls proportionate to the service model.

  • Public-site security baseline
  • Security headers where configured
  • Controlled handling of enquiries and personal information

Legal and data-protection framework

The Trust Centre should be read alongside the Group's privacy, data-processing, acceptable-use, cookie and AI notices. Those pages describe the legal framework; this centre describes the security and assurance position.

Responsible disclosure

If you believe you have found a security issue, report it in good faith and avoid accessing, altering or retaining data beyond what is reasonably necessary to demonstrate the issue. Reports are triaged and handled according to risk.

contact@theraeburngroup.com

Last reviewed: 29 August 2026. The Trust Centre is an assurance and transparency resource, not a certification. Sensitive internal security information is not published openly.