v2026.05 · LAST REVIEWED 14 MAY
Trust, Security & Compliance

How we are accountable.

A page for the procurement and security teams who need to confirm we are who we say we are. Numbers, certificates, policies and contact points — all on one page, kept current. Boring on purpose.

At a glance
Company no.
16438393
ICO
Registered
Cyber Ess.
In progress
PI cover
£3m
Incorporated
May 2025
01
Public record

Company facts.

Everything procurement needs for vendor onboarding. Click any line to copy it to your clipboard.

Legal entity
Cloudbliss Ltd
Company number
16438393
Registered in
England and Wales
Date of incorporation
8 May 2025
Registered office
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
SIC code
62012 — Business and domestic software development
SIC code
62020 — IT consultancy activities
VAT number
Pending registration TBC
UTR
Available on request
02
Cover in force

Insurance policies.

Certificates available on request via procurement@cloudbliss.co.uk.

Active
Professional indemnity
£3,000,000
Hiscox · Renewed Apr 2026
Active
Cyber liability
£1,000,000
CFC · Renewed Apr 2026
Active
Public liability
£1,000,000
Hiscox · Renewed Apr 2026
Active
Employer's liability
£10,000,000
Hiscox · Renewed Apr 2026
03
UK GDPR

Data protection.

How we register, who is responsible, and what we hand to a client at engagement.

ICO registration
ZB987654Registered
Data Protection Officer
Krutarth Shah · dpo@cloudbliss.co.uk
Lawful basis
Legitimate interest · Contract · Consent
Data residency
UK South · Microsoft Azure & 365
Available documents
Privacy policy
Public
Read →
Data retention policy
On request
Request →
Data processing agreement (DPA)
Template ready
Request →
Sub-processor register
Current
Read →
Breach response plan
Internal
Request →
04
Programmes in flight

Security certifications.

What we have today, what is in flight, and the target dates for the rest. Updated when state changes.

IASME
In progress

Cyber Essentials

Target: Q3 2026
65%
IASME
In progress

Cyber Essentials Plus

Target: Q4 2026
40%
UKAS body, TBC
Planned

ISO 27001

Target: 2027
10%
Microsoft
In progress

Microsoft Solutions Partner — Modern Work

Target: 2026
55%
Microsoft
In progress

Microsoft Solutions Partner — Business Apps

Target: 2026
45%
Information Commissioner
Achieved

ICO Data Protection registration

ZB987654
100%
05
Practising what we recommend

How we secure our own estate.

We run the same controls we recommend to clients. Every Cloudbliss account has MFA enforced through Conditional Access, no exceptions for founders. Devices are Intune-managed with compliance baselines, encryption and screen-lock policies. Client data lives in dedicated SharePoint sites with sensitivity labels and access reviews every quarter.

We do not store client credentials. Where access is needed we use Just-In-Time elevation through the client tenant. Internal Copilot use is restricted to public-context prompts. The practices we ask clients to adopt are the practices we already live with.

MFA on every account
01
Conditional Access — risk-based sign-in
02
Intune-managed devices, compliance enforced
03
Sensitivity labels on client data
04
Quarterly access reviews
05
Just-In-Time access to client tenants
06
Annual phishing simulation
07
Encrypted backups, 30-day retention
08
06
The fast lane

For procurement teams.

One inbox. Faster turnaround than your last vendor. Most onboarding packs are returned within two working days.

Procurement contact
info@cloudbliss.co.uk

Address NDAs, vendor questionnaires, insurance certificates, banking details, W-8BEN, DPA — anything supplier onboarding asks for — to this inbox. Watched by two of the founding team.

Standard onboarding pack
NDA — Cloudbliss template or yours
DPA — UK GDPR-compliant template
Insurance certificates (PI · Cyber · PL · EL)
Standard T&Cs
Modern Slavery statement
Anti-bribery & corruption policy
Banking details — secure channel
W-8BEN / W-9 — on request