Platform
Fenwick Harbour Assurance builds evidence management software for teams that must answer questions about their own controls on demand. We collect evidence from the systems you already operate, keep it mapped to the frameworks you are assessed against, and make the present state of any control something you query rather than reconstruct.
The problem
Assurance is still largely run as an annual reconstruction. Screenshots are gathered by hand, spreadsheets drift, and a team spends weeks assembling a picture of a system that has already moved on. The deeper cost is the blind spot: on an ordinary working day nobody can say whether a control is actually holding.
What we provide
- Scheduled read-only collection from cloud accounts, identity providers, ticketing systems and code hosts
- Control definitions held independently of any single framework and mapped outward, so one piece of evidence satisfies every scheme it belongs to
- Exception registers with named owners, expiry dates and a full trail of who accepted what and when
- Time-boxed reviewer workspaces letting an assessor read evidence without access to the underlying systems
Who we work with
Customers typically run between two hundred and four thousand people across financial services, health technology and public sector supply chains. They share a shape: a small assurance function accountable for a far larger control environment, working alongside an engineering organisation with no patience for manual screenshots.
How we operate
We run as a managed service inside the European Union with an optional customer-managed key arrangement, and there is no agent to install on production hosts. Evidence is encrypted in transit and at rest, tenant data is logically separated, and every read is attributed to an authenticated principal. Staff access to production requires hardware-backed authentication and is granted per task rather than standing.
Assurance and disclosure
We are assessed annually against ISO 27001 and SOC 2 Type II, with external penetration testing twice yearly. We welcome reports from security researchers at security@w18h.connectumo.com and aim to acknowledge within two working days.
Getting started
Engagements begin with a scoping session covering frameworks in play, the systems holding evidence, and the review calendar. Most teams have a first framework mapped and collecting within three weeks. Historical evidence does not need migrating; prior artefacts attach as static records and are superseded as live collection takes over.