Trust Centre

Security Metrics

A deliberately safe subset of Raeburn Consulting's security and resilience assurance metrics. We publish evidence-backed status and avoid turning internal security telemetry into unnecessary attack intelligence.

Last reviewed: 27 August 2026

Disaster-recovery exercise

Completed

Continuity and disaster-recovery procedures have been exercised, including technical backup restore testing.

Technical backup restore test

Completed

A technical restore test has been completed to validate operational recoverability.

Access review

Tracked internally

Access and privileged-access assurance is maintained internally; the exact review date is not published here without a current dated evidence record.

Vulnerability scanning

Operational

Security scanning forms part of the secure-development and vulnerability-management programme. Detailed findings and scan dates are retained internally.

Independent penetration test

Not currently claimed

No independent penetration-test result is published until a genuine current report is available.

Security training completion

Tracked internally

Training/awareness evidence is managed internally. A public completion percentage is published only when supported by a current measurement.

WCAG 2.2 Level AA

Passed

The public website has completed and passed accessibility testing against WCAG 2.2 Level AA.

CSA STAR for AI

Self-assessment evidence

STAR for AI / CAIQ material is treated as self-assessment and transparency evidence, not independent certification unless separately obtained.

Unresolved critical vulnerabilities

Not publicly asserted

We do not publish a zero count unless it is supported by a current, scoped vulnerability record at the time of publication.

Uptime

Not asserted on this page

A percentage is not published here until it is backed by an authoritative measured reporting period.

Internal measurement

Internally, assurance is broader and can include access and privileged-access reviews, vulnerability and dependency findings, secure-development checks, incident and recovery exercises, supplier assurance, privacy governance, AI-security controls, training evidence, remediation status and service reliability. Public figures are promoted to this dashboard only when their scope, measurement date and evidence are suitable for external reliance.

Assurance enquiries

Enterprise customers requiring additional due-diligence evidence can contact security@theraeburngroup.com. Privacy enquiries should be directed to dpo@theraeburngroup.com.