Trust centre

Governance & data handling.

Written for buyers in regulated settings — local authorities, NHS bodies and housing associations. This page states what is in place today, and what is still planned. Where something is on our roadmap, we say so.

01Verification

One verification badge.

Every organisation and every named person on OTHRS is either Verified or carries no badge at all, so counterparties always know exactly what has been checked.

  1. 01

    Verified

    Identity, legal entity and profile details independently verified.

Verified is earned, not requested: an organisation reaches it through a confirmed match on the Companies House register, and a person reaches it either through a fully completed profile or by being an active team member of a Verified organisation. Every manual verification decision is recorded against the member of staff who made it.

02Data visibility

Contact and commercial detail is withheld by default.

OTHRS separates the information that makes an organisation discoverable from the information that identifies and reaches it. The second set is held separately and released only where there is a working relationship.

Visible to the network
  • Organisation name, logo, description and headline
  • Sectors, regions and services covered
  • Verification status and any accreditations the organisation has published
  • Named people at the organisation, with role and professional profile
  • Live demand and opportunity listings the organisation has chosen to publish
Held privately
  • Direct email addresses and phone numbers for people and organisations
  • Billing and finance contact names and email addresses
  • Company registration numbers and VAT numbers
  • Seat assignments, invoices and other billing records
  • Documents shared inside a Deal Room, and their version history
  • Verification evidence submitted to the OTHRS team

Enforced by the platform, not the interface

Private fields are stored apart from public organisation and profile records, and access is decided when the data is requested. Hiding a field in the interface is not how we protect it.

Released with the relationship

Where a match, introduction or Deal Room connects two organisations, identifying and contact detail becomes available to the parties involved — and not to anyone else.

Browsing shows less than you expect

Before a connection exists, listings and directory records can appear without the owning organisation named. This is deliberate, so early-stage pipeline is not exposed to the wider market.

03Security roadmap

What is in place, and what is planned.

Procurement teams need the difference stated clearly, so we separate the two. Anything marked planned is not in place today.

  • Two-factor authentication (TOTP)

    Members can set up an authenticator app from account security settings, and remove it again. It is available to every account today and is optional — OTHRS does not currently require it, and organisation-wide enforcement is on our roadmap.

    In place
  • Staff action audit trail

    Administrative actions taken by OTHRS staff are recorded, including who acted and what changed.

    In place
  • ICO registration

    Registration with the Information Commissioner's Office is on our roadmap. We are not claiming it as complete on this page until it is confirmed, and we will publish the registration reference here when it is.

    Planned
  • Independent security testing and certification

    External penetration testing and formal certification are on our roadmap. We hold no security certification today and make no claim to one.

    Planned
04How we handle your data

The short version.

The full detail, including lawful bases, retention periods and processors, is set out in our Privacy Policy.

  • We collect what the platform needs to work

    Account and profile details, organisation information, and the listings, matches and messages you create on OTHRS.

  • We do not sell your data

    Your information is used to operate OTHRS and connect you with other members — not sold or licensed to third parties.

  • You keep control of what is published

    You choose what appears on your organisation profile and which demand or opportunity listings go live.

  • You can exercise your UK GDPR rights

    Access, correction, deletion, restriction, portability and objection. Requests go to our privacy contact and are handled within the statutory period.

  • Data is encrypted in transit and at rest

    Provided by our hosting and database platform. We have no independent certification of this and do not claim one.