Business intelligence built with purpose and accountability.
How we approach purpose, scope, customer control and clear boundaries on the work we take on. Set out in plain terms, so the scope is understood before a project starts.
What you can rely on
Written from your side of the table: what you are able to do, and answer for, because of how we work.
Business information, for business purposes
Organizational information that companies publish about themselves. We are not building personal profiles, and we do not want to.
Source context is part of the specification
The specification we agree sets out which fields carry source context and how it is recorded, so the scope is defined before work begins.
Scope agreed before work begins
We agree project scope and the applicable requirements with you in writing before any work starts.
What we refuse
These are the boundaries of the work we take on, set out plainly so they are clear before a project starts.
- No bypassing access controls. Nothing behind a login, a paywall or a CAPTCHA. Where access is restricted, that is the end of it.
- No private or logged-in areas. Personal accounts and private profiles are out of scope, whoever is asking.
- No purchased breach or leaked data. Ever, from any source, at any price, for any deadline.
- No suppliers who will not say where a list came from. If its origin cannot be stated, we do not buy it and you never see it.
- No covert monitoring. We will not build employee surveillance, and outreach features require authorization and proper disclosure.
- No sensitive personal data. Health, beliefs, politics, and the rest of the special categories are simply not our business.
- No proceeding on an optimistic reading. Where a rule is genuinely unclear, we stop and ask rather than assume in our own favor.
What we do not claim
We hold no third-party security certification today. When we hold one, it will be named here with its scope and the date it was issued. Plenty of suppliers imply a certification through careful wording; we would rather you knew.
We are not your legal advisers. We take our own obligations seriously and build to them, but how you use what we deliver is a decision your organization owns.
Compliance is not a guarantee of results. Working within an agreed scope sometimes means a smaller, better-defined set of companies — which is usually the more useful result.
Security
What protects the information you send us today, described accurately. Where a control is not yet in place, it says so — a security page that lists only strengths is not a security page.
Encrypted in transit
The enquiry form is served and submitted over HTTPS.
Restricted access
Enquiries are stored privately in the site database. They are not published, not exposed to search engines and not served over a public API. Access is limited to the site administrator account — this describes access within the website, not isolation at server level.
Minimal collection
Six fields, three of them optional. We do not ask for payment details, we hold none, and we do not run advertising trackers on this site.
What we do not claim
- No ISO 27001 or SOC 2 certification. We hold neither. Vendors in this category often do, and if that is a procurement requirement for you, we are not yet the right supplier.
- No penetration test to publish. None has been carried out on this site.
- No dedicated infrastructure. This site runs on shared hosting alongside other MarketAlong sites.
- No customer portal, and therefore no customer logins to protect. When one exists it will be described here first.
These are stated because you would find them out during procurement anyway, and hearing them from us first is the point of this page.
Ask us anything on this page.
If your legal or procurement team has a question, put it on the brief and you will get a direct answer before you commit to anything.