Trust Centre

Evidence room

Last updated 10 July 2026

This is the evidence register, not a claim that every item is complete. Drafts can be shared for review where appropriate; certificates, signed terms and test reports are shared only after they exist and are approved.

Evidence register

Internal DPIA
our data protection impact assessment, kept current
Customer DPIA support pack
everything your DPO needs, copy-paste friendly
Data processing agreement (template)
Article 28 terms for review before signature
Detailed sub-processor register
with transfer mechanisms per supplier
Data retention & deletion policy
full schedule
Security controls summary
control-by-control, including the roadmap
DSPT status evidence
as the toolkit submission progresses
DTAC readiness assessment
section-by-section position
DCB0129 evidence
applicability assessment and hazard-log summary; safety case as it completes
Insurance certificates
as policies are placed
Penetration test — executive summary
after the first external test
Architecture & data-flow diagram
systems, locations and flows

How to request access

Email hello@ayrisiq.co.uk with your name, organisation and what you're evaluating. Existing customers can ask their account contact; procurement and DPO teams welcome.

What stays internal

Some material is never shared, even under NDA — full penetration-test reports, open vulnerability details, internal risk registers, incident runbook contact chains and supplier contracts. Where you need assurance on those areas we share executive summaries, remediation confirmations, or walk them through with you on a call.