Cyber Essentials is the fastest, lowest-cost, government-backed baseline we can put in front of UK procurement teams. It gives buyers an independently assessed signal of core cyber hygiene within weeks — not months — while the deeper ISO 27001 and SOC 2 work is still being built out underneath it.
Cyber Essentials assesses five control themes. Here is what each one means and where RaptorFM stands today.
Boundary firewalls and internet gateways protect every device and network segment.
RaptorFM is hosted on Vercel. Every deployment sits behind Vercel's edge network, which provides network-layer filtering and DDoS mitigation by default — there is no separate customer-managed firewall on this platform, and no ports or services are exposed outside of it.
Devices and software are configured to reduce vulnerabilities and disable unnecessary functionality.
Application secrets and configuration are managed exclusively through environment variables and Vercel's encrypted environment variable store. No default credentials or secrets are ever committed to source control — .env files are excluded from the repository entirely.
Software and operating systems are kept up to date, with security patches applied promptly.
GitHub Dependabot runs weekly against every application dependency, GitHub Action and the Docker base image, opening a pull request automatically the moment a known vulnerability is published. Vercel manages underlying infrastructure and runtime patching automatically as part of the platform.
Access to data and services is limited to those who need it, with accounts managed through their lifecycle.
8-tier role-based access control is enforced and audited across every authenticated product API route today, with verified multi-tenant data isolation between organisations.
Defences are in place against viruses and other malware across all devices.
Microsoft Defender runs on every staff device, updating automatically via Windows Update.
Cyber Essentials Plus — the independently verified, on-site/technical-testing version of this certification — sits on our longer-term roadmap once Type verification budget allows.
Get our security overview, DPA, subprocessor list, policy set and current certification status — under NDA where required.