Technical assurance

Organisations trust us with important digital services, existing applications and sensitive operational processes. We make security, quality and delivery responsibilities explicit at the start of an engagement so that technical, procurement and governance teams can evaluate how we will work together.

Certifications and procurement

  • ISO/IEC 27001:2022 certified: our information security management system is independently certified.
  • Cyber Essentials Plus certified: our technical controls have been independently verified against the Cyber Essentials Plus standard.
  • Crown Commercial Service supplier: Bit Zesty services are available through the UK Government Digital Marketplace.
  • Established UK company: Bit Zesty Ltd has operated since 2009 and is registered in England and Wales under company number 06883289.

Certification is only part of technical assurance. The controls and evidence needed for a particular service depend on its users, data, hosting environment and operational importance. We agree those requirements with the client rather than treating one delivery model as appropriate for every system.

Security and quality in delivery

Our delivery approach can include:

  • technical and security assessment of an existing application before takeover;
  • automated testing, quality assurance and code review;
  • dependency, framework and security updates;
  • access controls and separation of responsibilities;
  • monitoring, incident response and post-incident learning;
  • accessibility work aligned with WCAG and relevant public-sector standards;
  • documented technical decisions, priorities and delivery risks; and
  • third-party security testing when required by the service.

The exact activities, responsibilities, support coverage and escalation arrangements are agreed for each engagement. We do not describe a service as continuously monitored or available around the clock unless that coverage has been included in the agreement.

AI and automation assurance

We apply the same engineering discipline to AI that we bring to complex software. Before moving an AI feature into production, we consider the business outcome, data boundaries, model and provider choice, evaluation, failure modes, human oversight, auditability, operating cost and ongoing monitoring.

Our Watchkeeper AI agent demonstrates this controlled approach. The operating system supplies the security evidence, the agent reviews that evidence within documented constraints, and a person remains responsible for investigating alerts and approving changes.

Evidence from client delivery

  • GOV.UK Trade Tariff involved replacing a complex legacy system, protecting data integrity during migration and operating a service used millions of times each month.
  • King’s Awards for Enterprise included malware scanning, an independent security audit and delivery to government service standards.
  • Easol included multi-factor authentication, more granular permissions, Rails upgrades and performance improvements while working inside an established engineering team.
  • Serious Readers involved taking over a business-critical e-commerce application, stabilising hosting and supporting payment and ERP integrations.

Supplier due diligence

If you are evaluating Bit Zesty for a project or support engagement, contact our client services team. Tell us which security, procurement, accessibility or operational requirements apply, and we will identify the relevant evidence and people for the conversation.

Our public policies include our privacy notice, accessibility statement, modern slavery statement and carbon reduction statement.