Handling the UK's most sensitive records for nearly 50 years means our security and quality are certified, audited and documented — not just claimed. Our management systems are independently certified to the ISO standards, and our scanning and destruction operations run in documented compliance with the relevant British Standards. Certificates and our ISMS scope statement are available on request.
Our ISO management systems are independently certified and re-audited on their own cycles; our scanning and destruction operations run in documented compliance with the relevant British Standards. Copies of every certificate, and our current scope statements, are available on request.
A certified ISMS governing how we protect information across our people, facilities and systems — risk assessment, access control, encryption, monitoring, incident response and continual improvement.
A certified quality management system — defined, audited processes with quality control on every project so output is consistent and accountable.
A certified environmental management system covering responsible handling, recycling and the environmental impact of our operations.
We scan in compliance with BS 10008, the British Standard for the legal admissibility and evidential weight of electronic information — so digitised records stand up as evidence and originals can be confidently destroyed.
Confidential material destroyed in compliance with BS EN 15713, with a certificate of destruction issued for every collection.
Registered with the ICO (reference Z6579030) and processing under UK GDPR and the Data Protection Act 2018, with documented lawful bases and data-processing agreements.
UK-owned since 1977. We never offshore your records — every stage is handled by our own vetted people, in our own accredited UK facilities.
Processed under documented lawful bases, with data-processing agreements and DPIAs where required.
Registration reference Z6579030. Data-protection queries: dataprotection@storafile.co.uk.
Stored, scanned, processed and destroyed in the UK — never sent overseas, unlike foreign-owned rivals.
DBS-checked drivers and operators, role-based access, and a full barcoded chain of custody.
The control areas our ISMS is built on — the practical measures behind the certificate.
Role-based access to client records, least-privilege by default, and access logged and reviewed.
Data encrypted in transit and at rest, delivered by SFTP, secure portal or encrypted media.
Every box, file and record barcoded and tracked from your door to our secure site and back, with a full audit trail.
For AI-assisted processing, identifiers are detected and tokenised in the UK before any content reaches our AI engine — see our AI & Data Protection Statement.
Accredited UK facilities with monitored, access-controlled premises and secure destruction on site.
Documented incident response with the 72-hour statutory breach duty assessed, plus business-continuity planning.
Copies of our ISO 27001, ISO 9001 and ISO 14001 certificates, and our BS 10008 and BS EN 15713 compliance statements and scope statement — request a copy or email compliance@storafile.co.uk.
How identifying data is protected in our document-processing pipeline — read the statement.
What personal data we hold, why, and your rights — read the policy.
Our standard terms of business — download the PDF.
Whether you're running a supplier audit, a tender or an information-governance review, we'll send our certificates, scope statement and the answers you need — usually the same working day.
Contact our compliance teamYes. We operate an Information Security Management System certified to ISO/IEC 27001, covering our people, facilities and the systems we use to store, scan, process and destroy client records. Our current certificate and scope statement are available on request.
Yes — copies of our ISO 27001, ISO 9001 and ISO 14001 certificates, and our BS 10008 and BS EN 15713 compliance statements, and our ISMS scope statement, are available on request. Email compliance@storafile.co.uk or call 0800 281857.
Entirely in the UK. Stor-a-File is UK-owned and every document is stored, scanned, processed and destroyed in our own accredited UK facilities by our own vetted staff. We never offshore your records.
Yes. Our drivers and operators are DBS-checked, work under a documented barcoded chain of custody, and access to client records is role-based and logged.
Yes. We are registered with the Information Commissioner's Office (registration reference Z6579030) and process personal data under UK GDPR and the Data Protection Act 2018, with documented lawful bases, data-processing agreements and a data-protection contact at dataprotection@storafile.co.uk.