Securemark

We build web and mobile applications for organisations that hold data other people trust them with.

Securemark has spent years testing other people's systems and finding what was missed. We build them now as well, and the same habits apply. Everything we build works on a phone and scales up to the desktop from there. We test the things that keep data where it belongs. We write down why every decision was made, so you are never dependent on us to understand your own system.

09:41

AQB Comply

Compliance today
Renewals, next 12 weeksThis week

14 Beech RoadGas certificate expires in 9 daysDue

2a High StreetEICR overdue, engineer assignedOverdue

77 Park LaneJob sheet submittedReview

TodayThis weekCertificates

Systems we build and run

  • AQB Comply
  • PageScan
  • Folken Technology

What we do

What we build

Software people use to get a job done. Certificates, case files, schedules, payments, records that have to be right. Usually replacing a spreadsheet, a paper file, or a system nobody has been able to change for years.

You will talk to the person writing the code, and you will see it working on a real address you can open on your phone long before the end.

  1. Web applications for people who have to get it right

    Client portals, back-office systems and record keeping for organisations where somebody has to answer for the data. Built so one customer's information cannot reach another's, and tested on every change to prove it.

  2. Mobile from the first screen

    Everything works on a phone and scales up to the desktop. AQB's engineers use theirs one-handed, standing in a customer's property, often with barely any signal.

  3. Compliance and record keeping

    Certificates, renewals, job sheets and the evidence behind them, with the dates and the audit trail right. The unglamorous part that decides whether the system was worth buying.

  4. Accessible as we build, not afterwards

    Built to WCAG 2.2 level AA and checked automatically on every change, with the evidence and the accessibility statement ready for you to publish.

What the suite checks

  • Semantic structure and heading order
  • Colour contrast at 4.5:1, both themes
  • Reflow at 320px with no sideways scroll

Runs onevery change

Mobile first

Built for the phone first

The people who use a system are often nowhere near a desk. They are on a train, in a car park, or standing in someone's kitchen with one hand free. If it does not work there, it does not work.

Big enough to hit with a thumb

Every button and link clears 44 pixels, the minimum a thumb needs.

Works before the JavaScript does

The menu works with a keyboard, a screen reader, and no script at all.

Tested at 320 pixels

The narrowest screen still in real use, checked on every change.

No mouse, no perfect signal

Nothing needs a hover, and nothing falls over on a weak connection.

The panel in the hero is the real thing, running in your browser as you read this. Scroll it, tab through it, or open this page on your phone and see.

How we work

How we work

You talk to the person building it. Everything gets written down, so nothing depends on anyone remembering.

  1. Start with the job people actually do

    We look at how the work happens today, spreadsheets and workarounds included. The system has to fit around that, because the people doing the job are the ones who decide whether it was worth it.

  2. Write the decisions down

    Every architectural and data protection decision is recorded with the reasoning behind it. A year later you can see why something is the way it is, and so can whoever takes over from us.

  3. Show you working software early

    You get something real on an address you can open on your phone, in small pieces, from the first few weeks. You can see the progress yourself instead of reading about it.

  4. Test the things that protect data

    Access control, keeping one customer's data away from another's, and every route that carries personal information are covered by tests that run on every change. Broken access control is the most common serious flaw in web applications, so that is where we spend the effort.

  5. Hand over something you own

    Your code, your accounts, your data, all documented and handed over properly at the end of the work, so the system is yours to run.

Easy to skip, expensive to add later

The things people leave until last

Data protection you can show someone

We collect only the personal data you actually need, limit who can see it by role, test that the limits hold, and keep it out of the logs. The documentation a DPIA asks for is written as we build, so it is ready when someone asks.

Accessibility, built in as we go

We build to WCAG 2.2 level AA and hand you the evidence and the accessibility statement to publish. If you have a legal duty to meet that standard, you have the proof. If you do not, you still reach the roughly one person in five who needs it.

A record of who did what

At some point somebody will ask who changed a record, when they changed it, and what it said before. A system that was not built to keep that history has no way to produce it later, because the information was never written down anywhere. We design it in from the first day, when it costs almost nothing.

Delivered with accredited partners

We also test and monitor

Securemark began as a testing and monitoring practice and still runs both. Finding other people's mistakes for a living changes how you build your own.

Penetration testing

Infrastructure, web and mobile application testing, and red team work, carried out by CREST certified and NCSC CHECK approved consultants.

You get a fixed price, a report the board and the engineers can both read, and a ranked list of what to fix first.

Delivered with our accredited testing partner

Managed detection and response

Round the clock monitoring of endpoints, network traffic and logs, run from a UK security operations centre with tested response playbooks.

The team investigates what it finds and acts on it. You do not have to staff a dashboard to get the benefit.

Delivered with our accredited SOC partner

Get in touch

Start a conversation

Tell us what you are trying to do and we will tell you honestly whether we are the right people for it. If we are not, we can usually point you at someone who is.

Prefer email? dom@securemark.io

We use what you send here to reply to you and for nothing else. It is not added to a mailing list and it is not shared.