Home / Compliance & Accreditations
Trust · Compliance & accreditations

Compliance you can evidence.

Handling the UK's most sensitive records for nearly 50 years means our security and quality are certified, audited and documented — not just claimed. Our management systems are independently certified to the ISO standards, and our scanning and destruction operations run in documented compliance with the relevant British Standards. Certificates and our ISMS scope statement are available on request.

ISO 27001 certified ISMSUK-owned, nothing offshoredSince 1977
ISO 27001Information security management
ISO 9001Quality management
ISO 14001Environmental management
BS 10008Legal admissibility of scans
BS EN 15713Secure destruction
UK GDPRICO reg. Z6579030
Certifications & standards

The standards we work to.

Our ISO management systems are independently certified and re-audited on their own cycles; our scanning and destruction operations run in documented compliance with the relevant British Standards. Copies of every certificate, and our current scope statements, are available on request.

ISO 27001

Information security management

A certified ISMS governing how we protect information across our people, facilities and systems — risk assessment, access control, encryption, monitoring, incident response and continual improvement.

ISO 9001

Quality management

A certified quality management system — defined, audited processes with quality control on every project so output is consistent and accountable.

ISO 14001

Environmental management

A certified environmental management system covering responsible handling, recycling and the environmental impact of our operations.

BS 10008

Legal admissibility

We scan in compliance with BS 10008, the British Standard for the legal admissibility and evidential weight of electronic information — so digitised records stand up as evidence and originals can be confidently destroyed.

BS EN 15713

Secure destruction

Confidential material destroyed in compliance with BS EN 15713, with a certificate of destruction issued for every collection.

UK GDPR

Data protection

Registered with the ICO (reference Z6579030) and processing under UK GDPR and the Data Protection Act 2018, with documented lawful bases and data-processing agreements.

Data protection & sovereignty

Your data stays in the UK, in our hands.

UK-owned since 1977. We never offshore your records — every stage is handled by our own vetted people, in our own accredited UK facilities.

UK GDPR & DPA 2018

Processed under documented lawful bases, with data-processing agreements and DPIAs where required.

ICO registered

Registration reference Z6579030. Data-protection queries: dataprotection@storafile.co.uk.

No offshoring

Stored, scanned, processed and destroyed in the UK — never sent overseas, unlike foreign-owned rivals.

Vetted people

DBS-checked drivers and operators, role-based access, and a full barcoded chain of custody.

Information security controls

Inside our ISO 27001 regime.

The control areas our ISMS is built on — the practical measures behind the certificate.

Access control

Role-based access to client records, least-privilege by default, and access logged and reviewed.

Encryption & secure transfer

Data encrypted in transit and at rest, delivered by SFTP, secure portal or encrypted media.

Chain of custody & audit trail

Every box, file and record barcoded and tracked from your door to our secure site and back, with a full audit trail.

Pseudonymisation

For AI-assisted processing, identifiers are detected and tokenised in the UK before any content reaches our AI engine — see our AI & Data Protection Statement.

Physical & facility security

Accredited UK facilities with monitored, access-controlled premises and secure destruction on site.

Incident & continuity management

Documented incident response with the 72-hour statutory breach duty assessed, plus business-continuity planning.

Evidence & documents

What we can share.

Certificates & ISMS scope

Copies of our ISO 27001, ISO 9001 and ISO 14001 certificates, and our BS 10008 and BS EN 15713 compliance statements and scope statement — request a copy or email compliance@storafile.co.uk.

AI & Data Protection Statement

How identifying data is protected in our document-processing pipeline — read the statement.

Privacy & Cookie Policy

What personal data we hold, why, and your rights — read the policy.

Terms & Conditions

Our standard terms of business — download the PDF.

Compliance team

Need our certificates or a due-diligence pack?

Whether you're running a supplier audit, a tender or an information-governance review, we'll send our certificates, scope statement and the answers you need — usually the same working day.

Contact our compliance team
Frequently asked questions

Compliance FAQs

Is Stor-a-File ISO 27001 certified?

Yes. We operate an Information Security Management System certified to ISO/IEC 27001, covering our people, facilities and the systems we use to store, scan, process and destroy client records. Our current certificate and scope statement are available on request.

Can we see your certificates?

Yes — copies of our ISO 27001, ISO 9001 and ISO 14001 certificates, and our BS 10008 and BS EN 15713 compliance statements, and our ISMS scope statement, are available on request. Email compliance@storafile.co.uk or call 0800 281857.

Where is our data stored and processed?

Entirely in the UK. Stor-a-File is UK-owned and every document is stored, scanned, processed and destroyed in our own accredited UK facilities by our own vetted staff. We never offshore your records.

Are your staff vetted?

Yes. Our drivers and operators are DBS-checked, work under a documented barcoded chain of custody, and access to client records is role-based and logged.

Are you registered with the ICO and compliant with UK GDPR?

Yes. We are registered with the Information Commissioner's Office (registration reference Z6579030) and process personal data under UK GDPR and the Data Protection Act 2018, with documented lawful bases, data-processing agreements and a data-protection contact at dataprotection@storafile.co.uk.

Local document management: Leicester · Nottingham · Corby · London · Camberley · Wirral · Halifax · UK-wide coverage