Behind the badge: what's actually in Microform's new Trust Centre
If you've ever tried to onboard a new supplier who'll be handling your organisation's paper records, personal data or archival materials, you'll know the drill. A security questionnaire lands in someone's inbox. It sits there for a fortnight. Eventually a PDF comes back, half-answered, three certifications out of date. Everyone loses a week they didn't have.
We built the Microform Trust Centre to close that gap. Rather than write another "we take security seriously" page, we've put our actual certifications, policies and live security controls in one place, and made most of it available without a phone call. Here's what's in it, and why.
What is the Trust Centre, exactly?
It's a self-serve hub of everything a client or prospective client might need to vet us as a supplier: our compliance certifications, our security and privacy policies, and a live breakdown of the technical and organisational controls we run day to day. Some documents are open to anyone who visits; others (the more detailed policies) are available on request once you've verified who you are.
What certifications does Microform actually hold?
Three sit front and centre: ISO 27001:2022 for information security management, UK Cyber Essentials, and ISO 9001:2015 for quality management. Alongside those, we hold BS 10008:2020, the British Standard that governs the legal admissibility of electronically stored documents, which matters a great deal if you're relying on us to digitise records that need to stand up as evidence, plus our ICO registration and ISO 14001:2015 for environmental management. All of them are listed on the Trust Centre with links through to the certificates themselves, rather than just the logos.
How do I know this isn't just a page of badges?
Fair question: plenty of "trust centres" are exactly that. Ours is built on a platform that tracks our controls continuously, not just at certification renewal time, and the page itself shows when each section was last updated (typically within the hour). Underneath the certifications sit dozens of individual controls, grouped into five areas: infrastructure security, organisational security, product security, internal security procedures, and data and privacy. Things like network segregation, physical entry controls, secure development practices, and how we handle staff access when someone changes role or leaves. You can click into any category and see exactly what's covered, not just take our word for it.
Does this cover physical documents too, or just digital systems?
Both, which is really the point. Most trust centres are written for software vendors and focus entirely on cloud infrastructure. Ours has to cover that, because we run digital systems too, but it also has to cover what happens to a box of birth and death registers, medical records or historical bound volumes when it arrives at our premises: chain of custody, secure storage, controlled destruction, and staff vetting. BS 10008 and our internal information security policies speak directly to that physical-to-digital handover, which is where a lot of generic trust centres fall silent.
Who is this actually useful for?
Anyone who has to formally justify choosing us as a supplier, which in our client base is most people. Legal and financial firms running vendor due diligence, healthcare and public sector organisations with statutory data protection obligations, insurers, and local authorities and register offices handling records that need to remain legally valid for decades. If you've ever had to fill in a supplier security questionnaire yourself, you'll recognise exactly the kind of document we're now able to hand over in minutes instead of weeks.
What if I need something that isn't public: a specific policy, a penetration test summary, an audit report?
Request access through the Trust Centre itself. A number of documents, including our GDPR policy, information security policy, and audit programme details, are held behind a simple access request rather than published openly, which lets us share more detail than we'd put on a public page while still keeping control of who sees what.
Why now?
This isn't a response to any one trigger, it's the next step in something we've been doing for a while: looking for ways to make working with Microform easier, not just once you're a client, but from the first conversation.
Approving a new third-party supplier for anything involving personal data or legally sensitive records is rarely quick. Someone on your side is chasing certificates, waiting on legal or compliance sign-off, and filling in the same questionnaire in three slightly different formats, all before any actual work can start. It's a slow, often frustrating process, and it's time your team doesn't get back.
The Trust Centre is our answer to that friction. Instead of working through a bespoke questionnaire back and forth, you can pull our current certifications, policies and control detail yourself, in minutes, and request anything that isn't already public in a couple of clicks. It won't remove every step of your due diligence process, but it should remove a good few of them.
You can explore the Trust Centre at trust.microform.digital, or get in touch at info@microform.digital if there's something specific you need that isn't there.