How it is built, and what you are being asked to trust.
Most vendors answer a security question with a certificate. The more useful answer is architectural: what can we technically see, what can we technically do, and where have we deliberately removed ourselves from the equation.
Zero-knowledge where it matters
With PushItPro, content is encrypted before it reaches us. We hold ciphertext we cannot decrypt. That is not a policy commitment that could change with an owner or a jurisdiction — it is a property of the design.
Least data, not most data
Volarian shares documents view-only rather than distributing copies. FlashItSync holds files in object storage with only lightweight metadata alongside. Nothing collects more than the job requires.
Least privilege, and least dependency
Where a product reads from a system you already run — Entra ID, a vendor feed, an object store — it asks for the narrowest access that does the job, and it degrades rather than breaks when that access is withdrawn.
Small attack surface by construction
Nothing in the portfolio installs an agent fleet on your network. Fewer moving parts means fewer things to patch, fewer things to misconfigure, and a deployment an SME can actually reason about.
What we run on, and why
A modern serverless stack means a small team can run production infrastructure with real isolation and real resilience, without a data-centre bill to pass on. Authentication is delegated to a specialist rather than hand-rolled, which is the right call for a company this size and an unusual thing for a vendor to admit.
What we connect to
Integrations are chosen because SMEs and their providers already run these platforms, not because the logo looks good on a slide. Where a product integrates, it does so natively rather than through a generic connector layer. Confirm this list against what ships today before publishing — an overclaimed integration is the fastest way to lose a technical buyer.
| Question a buyer will ask | Our answer |
|---|---|
| Can your staff read our data? | For PushItPro and Volarian, no — the architecture prevents it. For the other products, access is role-restricted and logged; ask us for the specific answer per product. |
| Where is our data held? | [Confirm and state the region explicitly — Cloudflare supports jurisdictional restriction, and buyers in Scotland and the public sector will ask.] |
| Do you hold Cyber Essentials? | [State the position honestly — held, in progress with a date, or planned. Do not imply certification you do not have.] |
| Who are your sub-processors? | Cloudflare, Clerk and Neon, plus the operational tools listed in our privacy statement. The list is published and we give notice before it changes. |
| What happens if we leave? | Export paths out of every product. Per-product pricing means leaving one does not mean leaving all. |
| What happens if you are acquired or fail? | [Answer this before you are asked. For a small vendor it is the single most common objection, and a source-escrow or data-export commitment defuses it.] |