Trust Centre
Due diligence, answered directly
The information procurement, legal and security teams need to assess a LicenceLess engagement — ownership, data handling, security architecture, compliance, contracts, and how to raise a concern.
This page is a due diligence resource. The summaries below describe how LicenceLess operates; the definitive terms for any engagement are set out in the engagement documents. Contractual, data-protection and IP content is kept under review and each section carries the date it was last reviewed.
Platform ownership and IP transfer
The defining outcome of every LicenceLess engagement is that the client owns the platform outright. This section formalises, in plain terms, exactly what that means.
On completion of an engagement, the following transfers to the client: the complete platform codebase, all associated intellectual property, the platform data, and the infrastructure relationship on which the platform runs. LicenceLess retains no licence over a delivered platform and holds no ongoing rights to the code or the data.
This transfer is documented formally within the contractual framework (see Section F), through a defined IP transfer agreement executed at completion. Ownership is not a marketing position — it is a contractual commitment recorded in the engagement documents.
Last reviewed: September 2026
Data handling and storage
During development and delivery, client data is handled under the following principles.
- Storage during development: client project data is held within secure, access-controlled cloud environments. Hosting jurisdiction is agreed with the client and can be confined to the UK or EEA where an engagement requires it.
- Access: access to client data during an engagement is limited to the individuals directly working on the delivery, on a least-privilege basis, and is removed on completion.
- Protection: data is encrypted in transit and at rest during the engagement, using current industry-standard encryption.
- On completion: LicenceLess-side working copies of client data are removed once the platform and its data have been transferred into the client’s ownership, save for anything the client asks us to retain under a separate support agreement.
- Data protection commitments: for UK or EEA engagements, a data processing agreement can be put in place setting out the respective obligations of each party under applicable data protection law.
Data handled through this website (visitor data) is separate from project data and is covered by the LicenceLess Privacy Policy.
Last reviewed: September 2026
Information security
Security is treated as a foundational engineering concern throughout development and delivery, not an afterthought.
- Secure development: platforms are built following secure development practices, including role-based access control, secure authentication, encryption of data in transit and at rest, and audit logging appropriate to the platform’s purpose.
- Access controls: access to client environments during an engagement is managed on a least-privilege basis and reviewed as the engagement progresses.
- Standards: the specific security standards and any certifications relevant to a given engagement can be confirmed directly on request, so the position stated is always current and accurate rather than a generic badge.
- Incident handling: security concerns or vulnerabilities identified during an engagement are triaged and reported to the client promptly, with remediation agreed jointly.
- Post-handover: once a platform is delivered, LicenceLess retains no access to it unless the client explicitly engages us for ongoing support under a separate agreement.
Last reviewed: September 2026
Security architecture of delivered platforms
Every platform LicenceLess delivers is engineered with security as a foundational concern, using a defence-in-depth approach so that no single control is relied on alone. The controls below describe how the platforms we build are secured; because you own the platform, these controls operate within your own environment once it is delivered.
- Defence in depth: protection is layered across the network perimeter, the application and the data — combining a web application firewall and encrypted transport at the edge, validated and access-controlled application logic, and encrypted, access-controlled data storage.
- Encryption: data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are held in a managed key vault within your environment, so the keys that protect your data remain under your control.
- Authentication and access: platforms support enterprise single sign-on (including SAML 2.0 and modern identity providers), multi-factor authentication for privileged and sensitive operations, and role-based access control so each user has only the permissions their role requires.
- Application security: platforms are hardened against the OWASP Top 10 — including parameterised database access to prevent injection, protection against cross-site scripting and request forgery, and rigorous input validation.
- Audit logging: security-relevant events — authentication, permission changes and data operations — are recorded in an audit log to support monitoring and compliance review. You control retention and access once the platform is yours.
- Dependency security: platforms are built with automated dependency scanning and a policy of no known critical vulnerabilities, using lock files for reproducible builds and a clear route to keep components patched over time.
Last reviewed: September 2026
Compliance alignment
LicenceLess platforms are built to established security and data-protection standards. We describe this as alignment rather than a generic badge: the frameworks below are the standards platforms are engineered to, and the formal certification position for any specific deployment is confirmed directly as part of an engagement.
- UK GDPR and data protection: platforms that handle personal data are designed to support lawful processing, data minimisation, configurable retention and data subject rights — access and export, rectification, erasure, and portability. For UK or EEA engagements a data processing agreement can be put in place.
- ISO 27001 (information security management): platforms and delivery practices are built to the principles of ISO 27001 across access control, cryptography, operations security, secure development and incident management.
- OWASP Top 10: application security is measured against the OWASP Top 10, with mitigations designed in for the most significant categories of web application risk.
Vulnerability management is ongoing by design — automated dependency scanning, static analysis and periodic review — and any security concern identified during an engagement is triaged and reported to you promptly, with remediation agreed jointly.
Last reviewed: September 2026
Contractual framework
A LicenceLess engagement is governed by a small, clear set of contractual documents, designed to be readable by the people who have to sign them.
- Standard documents: engagement terms, a statement of work defining scope and deliverables, and an IP transfer agreement confirming the ownership outcome described in Section A.
- Negotiable terms: scope, timelines and specific commercial terms are agreed per engagement. The ownership and IP-transfer position is not diluted — it is the point of the model.
- Confidentiality: LicenceLess is willing to enter into a mutual non-disclosure agreement before detailed discovery begins.
- Client-side MSAs: client master service agreements can be accommodated where their terms are compatible with the ownership model.
Full contract templates are not published here. For a detailed review, procurement and legal teams can contact us directly at [email protected].
Last reviewed: September 2026
Sub-contractors and third-party components
Platforms are built using well-established third-party and open-source components where doing so is in the client’s interest. This is managed so that it never compromises ownership.
- Third-party components: any open-source or licensed components used within a platform are selected so that they do not create licence dependencies that contradict the ownership model. The client receives a platform they can run, modify and maintain without an obligation back to LicenceLess.
- Licensing position: the licensing status of third-party components included in a platform is documented as part of the handover package, so the client has a clear record of what is in their platform and on what terms.
- Sub-contracting: where any additional specialist is involved in a delivery, they are bound by the same confidentiality and IP obligations that apply to LicenceLess, so the ownership outcome for the client is unaffected.
Last reviewed: September 2026
Raising a concern
If you need to raise a data protection, security or compliance concern, you can contact us directly and we will respond.
- Data protection queries: contact us at the address below and mark your message for the attention of data protection.
- Security concerns: report a suspected security issue to the same address; genuine security reports are prioritised.
- Response commitment: we aim to acknowledge any concern raised through these routes within five working days.
Contact: [email protected]
Last reviewed: September 2026
Questions answered? Let’s talk.
Once your due diligence questions are resolved, the next step is a conversation about your operation.
Book Discovery