generated: '2026-08-27' method: searched source: https://www.proactis.com/uk/about-us/accreditations-certifications/ docs: https://www.proactis.com/uk/about-us/accreditations-certifications/ provider: Proactis providerId: proactis name: Proactis accreditations and certifications description: >- Proactis publishes a named set of security, quality and assurance certifications on a public Accreditations & Certifications page. It is a marketing page rather than a trust portal — the certifications are named but no certificate, scope statement, audit report or subprocessor list is downloadable, and there is no request workflow for obtaining them. trust_portal: false trust_portal_url: null probed: - url: https://trust.proactis.com/ result: DNS does not resolve - url: https://www.proactis.com/.well-known/security.txt status: 404 certifications: - name: ISO/IEC 27001 domain: Information security management system certificate_published: false scope_published: false - name: ISO 9001 domain: Quality management system certificate_published: false scope_published: false - name: Cyber Essentials domain: UK NCSC baseline cyber security certification certificate_published: false scope_published: false - name: ISAE 3402 domain: Assurance report on controls at a service organization report_published: false type_published: false note: >- The page names ISAE 3402 but does not state whether the report is Type I or Type II, which is the distinction an auditor actually needs. - name: G-Cloud domain: UK Crown Commercial Service Digital Marketplace framework note: >- A public-sector procurement framework listing rather than a security certification. It matters commercially — Proactis sells heavily into UK local government, healthcare, housing and higher education, all named as target sectors on the site. not_found: - SOC 2 - PCI DSS - HIPAA - FedRAMP - ISO 27017 / 27018 / 27701 data_protection: privacy_policy: https://www.proactis.com/us/policies/privacy-policy/ data_processing_summary: https://www.proactis.com/us/policies/data-processing-and-cookies-statements/ subprocessor_list: not published dpa: not published publicly related_policies: - {name: Modern Slavery Statement, url: 'https://www.proactis.com/us/policies/modern-slavery-statement/'} - {name: Anti-Trust Policy, url: 'https://www.proactis.com/us/policies/anti-trust-policy/'} - {name: Accessibility Statement, url: 'https://www.proactis.com/us/policies/accessibility-statement/'} - {name: Product Accessibility, url: 'https://www.proactis.com/us/policies/product-accessibility/'} - {name: Intellectual Property Notice, url: 'https://www.proactis.com/us/policies/intellectual-property-notice/'} - {name: DMCA Notice, url: 'https://www.proactis.com/us/policies/dmca-notice/'} - {name: Cookies Policy, url: 'https://www.proactis.com/us/policies/cookies-policy/'} gaps: - >- No evidence is obtainable without a sales conversation. Certificate numbers, issuing bodies, validity dates and scope statements are all absent, so a buyer cannot verify any claim on the page. - No subprocessor list and no publicly available DPA. - >- No vulnerability disclosure policy and no security.txt (probed 2026-08-27, 404; no bug-bounty program found on HackerOne, Bugcrowd or Intigriti). A company holding ISO 27001 and Cyber Essentials and selling into UK public sector publishes no route for a researcher to report a flaw.