Business Security Practices
Convo has robust internal and vendor-focused security processes in place:
1. Vendor Management
SignLive Ltd trading as Convo 272 Bath Street, Glasgow, G2 4JR, United Kingdom go.convo.io/uk 4 ⁄ 6
- Third-party processors undergo security and privacy due diligence, incl. DPAs and data-transfer safeguards.
- Critical vendors are reviewed at least annually using financial, legal, and operational risk assessments.
2. Security Governance
- Our ISMS aligns to ISO/IEC 27001 and NIST CSF.
- We partner with an independent security firm for annual pen testing, incident response exercises, and risk reviews.
3. Employee Security
- Background Checks: Conducted only for roles where deemed necessary and relevant.
- Confidentiality Agreements: All staff and contractors sign confidentiality agreements.
- Security Training: Mandatory security awareness on hire and annually, including phishing, data handling, and incident reporting. Convo’s BSL interpreters are verified and appropriately registered (e.g., NRCPD or equivalent) and adhere to confidentiality obligations.
