Mabel HR
ServicesRecruitmentAIM&AAbout
Book intro
ServicesRecruitmentAIM&AAbout Book intro
Strategic HR Fractional HR Recruitment AI for HR M&A
Strategic HR consultant planning at a whiteboard Strategic HR Fractional HR adviser meeting with a business leader Fractional HR Recruitment professional coordinating a hire by phone Recruitment HR leader using AI-enabled workflows in a modern office AI for HR Two HR advisers reviewing merger and acquisition workforce plans M&A

Information security

Security

We take a risk-based approach to protecting the information entrusted to us. This page explains the organisational and technical safeguards we use, the responsibilities we share with clients and suppliers, and how to report a security concern.

Last updated 7 August 2026

On this page

1. Purpose and scope2. Our security approach3. Access and identity4. Devices, systems and cloud services5. Data handling and confidentiality6. Suppliers and subprocessors7. Backups and resilience8. Incident response9. People and working practices10. Client responsibilities11. Reporting a security concern12. Important limitations13. Review and updates

1. Purpose and scope

This page describes Mabel HR’s general approach to information security across our Website, internal operations and client delivery. It applies to the systems, information and suppliers we use to provide HR, payroll, workforce, global hiring and AI-related services.

Specific client engagements may require additional controls, security schedules, data-processing terms or documented responsibilities. Where agreed in writing, those engagement-specific requirements take precedence.

2. Our security approach

We aim to apply security measures that are proportionate to the nature of the information, the purpose of the processing, the systems involved and the potential impact of loss, misuse or unauthorised access.

Our approach is based on risk assessment, data minimisation, least-privilege access, secure configuration, supplier review, staff awareness, resilience planning and prompt investigation of suspected incidents.

No unsupported claims: this page does not state or imply that Mabel HR holds a particular security certification unless that certification is expressly confirmed in writing for the relevant service.

3. Access and identity

We seek to limit access to systems and information to people who need it for an authorised business purpose. Depending on the system and risk, controls may include:

  • named user accounts and role-based permissions;
  • multi-factor authentication where supported and appropriate;
  • strong password and credential-management practices;
  • review and removal of access when roles or engagements change;
  • separation of administrative access from routine use; and
  • restrictions on sharing accounts, credentials or authentication factors.

4. Devices, systems and cloud services

We use managed devices, software and cloud services appropriate to our work. Security measures may include supported operating systems, security updates, device locking, malware protection, secure network connections, encryption capabilities, configuration controls and monitoring provided by the relevant platform.

We select and configure cloud services with regard to the information being processed, available security features, access controls, contractual protections, service resilience and data-location considerations.

5. Data handling and confidentiality

We aim to collect, use and retain only the information reasonably needed for a defined purpose. Personal and confidential information should be stored and shared through approved systems and only with authorised recipients.

Our controls may include confidentiality obligations, restricted folders or workspaces, secure transfer methods, retention rules, deletion processes and checks before information is disclosed externally. Our handling of personal information is also governed by our Privacy Policy.

Users must not place passwords, secret keys or highly sensitive client information into unapproved tools, including public or consumer AI services. Our use of artificial intelligence is described in our AI Policy.

6. Suppliers and subprocessors

We may rely on third-party providers for hosting, communications, document management, productivity, forms, analytics, payroll-related operations or specialist delivery. We assess suppliers proportionately, taking account of the service, information involved, contractual terms, access model, security features, privacy commitments and business continuity.

Where a supplier processes personal information on our behalf, we seek appropriate data-processing terms and instructions. No supplier can eliminate all risk, so responsibilities and dependencies are reviewed as part of our wider risk management.

7. Backups and resilience

For systems and information where continuity is important, we consider appropriate backup, version-history, recovery and continuity arrangements. The measures available depend on the platform, the information involved and the responsibilities agreed with the client or provider.

We also seek to reduce single points of failure through documented processes, controlled access, supplier support and alternative working arrangements where proportionate.

8. Incident response

Suspected loss, unauthorised access, malware, phishing, credential compromise, inappropriate disclosure or material service disruption should be reported promptly. Our response may include containment, preservation of evidence, access changes, supplier escalation, impact assessment, recovery, communication and corrective action.

Where an incident involves personal information, we assess whether notification to affected organisations, individuals or the Information Commissioner’s Office is required under applicable data-protection law and contractual arrangements.

9. People and working practices

Information security depends on people as well as technology. We promote practical awareness of phishing, social engineering, secure sharing, confidentiality, device protection, data minimisation and prompt incident reporting.

People working for or with Mabel HR are expected to follow applicable policies, client instructions, contractual duties and approved working methods. Access and responsibilities should be reviewed when an engagement or role ends.

10. Client responsibilities

Security is a shared responsibility. Clients should provide accurate instructions, nominate authorised contacts, maintain suitable controls over their own systems and users, protect credentials, review permissions and tell us promptly about relevant incidents or changes in risk.

Where Mabel HR connects to or works within a client environment, the client remains responsible for the security and administration of systems under its control unless a written agreement expressly states otherwise.

11. Reporting a security concern

If you believe you have found a vulnerability, received a suspicious message claiming to be from Mabel HR, or become aware of a possible security incident involving us, please email hello@mabelhr.com with the subject line Security concern.

Please include enough information for us to understand the issue, but do not send passwords, secret keys, unnecessary personal information or exploit data that could increase the risk. Do not access, alter, download or disclose information beyond what is necessary to identify the concern.

We ask that security researchers act lawfully and in good faith. This page is not a formal bug-bounty programme and does not authorise testing, scanning, disruption or access to systems without written permission.

12. Important limitations

No organisation, website, network, cloud service or transmission method can be guaranteed completely secure or continuously available. Security controls reduce risk but cannot remove it entirely.

Descriptions on this page are general and may change as systems, suppliers, threats and legal requirements develop. They do not create a warranty, service level or contractual commitment unless incorporated into a signed agreement.

13. Review and updates

We review our security approach periodically and when material changes occur in our services, technology, suppliers, risk profile or legal obligations. The current version of this page is identified by the date shown above.

Questions about our security approach can be sent to hello@mabelhr.com.

Mabel HR

People-first HR support for growing businesses. Practical guidance, trusted expertise, flexible solutions.

Book a 30-min intro
Services
  • Strategic HR
  • Fractional HR
  • Recruitment
  • AI for HR
  • M&A
Company
  • About Us
  • Q&A’s
  • Terms & Conditions
  • Privacy Policy
  • AI Policy
  • Security
  • Contact Us
  • Sitemap
Get in touch
0203 411 1903 hello@mabelhr.com London, UK
Mabelhr Ltd · Registered in England & Wales No. 08171703 · VAT No. 520 1481 38
© 2026 Mabel HR. All rights reserved.