How we handle your data — and our own.
One page. Entity, independence, security, privacy, AI governance, sub-processors and the dated log of every material change. It describes controls enabled today. It is not an independent certification.
Entity and regulators
- Registered entityBawin Limited · England and Wales
- Company number17307761
- Registered officeBawin Limited
ZC210370 · expires 29 July 2027
Management system
Bawin operates an information security management system structured to ISO/IEC 27001:2022 Annex A, and an artificial intelligence management system structured to ISO/IEC 42001:2023 Annex A. Both are governed by the Core Policy Suite (BWN-SUITE-001, Edition 1.0, issued 2026-08-12), whose head document is the Company Core Policy.
Controlled documents
| Reference | Document | Edition | Effective | Next review | Availability |
|---|---|---|---|---|---|
| BWN-POL-CORE-001 | Company Core Policy | 4.0 | 2026-08-12 | 2027-08-12 | Public |
| BWN-ISMS-POL-001 | Information Security Policy | 1.0 | 2026-08-12 | 2027-08-12 | Public |
| BWN-ISMS-REG-005 | Statement of Applicability | 1.0 | 2026-08-12 | 2027-08-12 | On request |
| BWN-ISMS-TEC-001 | Technical Controls Specification | 1.0 | 2026-08-12 | 2027-08-12 | Internal |
| BWN-ISMS-POL-011 | Acceptable Use Policy | 1.0 | 2026-08-12 | 2027-08-12 | Internal |
Statement of Applicability — summary
Certification route
- Open
- Open
- Planned
- Scheduled
- Not yet pursued
Reading ourselves in public.
Bawin's own infrastructure — Frankfurt/London hosting, source control, identity — is being connected to Bawin's own method. The first public Bawin-on-Bawin reading is targeted for Q4 2026 and will publish live from that date.
Independence and integrity
Independence is a methodological commitment, not a marketing claim. The declared interests register, the recusal count and the list of what we will not sell are published alongside the arithmetic on the method page. The binding commitments are in the public company policy.
- We do not sell what we assess.
- No reading can be bought.
- Perceived conflicts are conflicts.
- Changes are published with their rationale.
Security and disclosure
In place today
Responsible disclosure
If you believe you have found a security vulnerability, report it to contact@bawin.co. Please give us reasonable time to investigate and remediate before public disclosure. We acknowledge within two working days and aim to triage within five. Machine-readable contact details are at /.well-known/security.txt.
Independent review cadence
Privacy notice
Bawin Limited processes personal data in two distinct roles. This is the whole notice. The entity statement is in the footer, once.
Two roles: controller and processor
What this website collects
Lawful basis
Product evidence (processor role)
Where it is stored
How long we keep it
Who we share it with
Your rights
AI governance
ISO 42001 is one of the frameworks Bawin maps, and the clause resolver is a headline feature. A short, specific statement of how our own AI is governed.
What the clause resolver is used for
What it is not used for
No third-party model provider is in use
Human review before it leaves the product
Model choice and provenance
ISO 42001 self-mapping
Sub-processors
| Provider | Role | Establishment | Processing region | Data reached | Foreign-access exposure |
|---|---|---|---|---|---|
| Cloudflare, Inc. | Edge delivery, TLS termination, DNS, DDoS protection | United States | UK/EU edge locations | Request metadata in transit. No evidence at rest. | Yes — ultimate parent is subject to the US CLOUD Act and FISA 702. |
| Hetzner Online GmbH | Application and database hosting | Germany | Germany (EU) | Evidence records, control state and account records at rest. | No — German parent, no extraterritorial disclosure regime. |
| Proton AG | Correspondence and transactional email, inbound and outbound | Switzerland | Switzerland (UK and EU adequacy) | Whatever a correspondent chooses to send us, and account correspondence. | No — Swiss parent, no extraterritorial disclosure regime. |
Invariant checks on this site
The checks below run against the deployed output, not the source tree. The build is served exactly as a visitor receives it, every route in the sitemap is crawled, every internal link and anchor is followed, and the assertions are made against the fetched HTML. A release that fails any one of them does not ship. This is the only place these checks are described, and it is described once.
Accessibility
Trust log
Every material change to the method, the spine and the trust posture, dated. A product built on the discipline of dated, versioned evidence should hold itself to it.
- 2026-08-12Policy
Core Policy Suite BWN-SUITE-001 Edition 1.0 issued, comprising the Company Core Policy (BWN-POL-CORE-001, Edition 4.0), the Information Security Policy (BWN-ISMS-POL-001, Edition 1.0), the Statement of Applicability (BWN-ISMS-REG-005), the Technical Controls Specification (BWN-ISMS-TEC-001) and the Acceptable Use Policy (BWN-ISMS-POL-011). The suite index is published at /policy/suite with every reference, edition, effective date, review date, classification and availability. Every edition number and date on the site now resolves from one constants module, so two surfaces cannot disagree.
- 2026-08-12Policy
Company Core Policy Edition 4.0 supersedes Edition 3.0 of 28 July 2026. Rationale: Edition 3.0 stated commitments without stating the order they bind in or the conditions that would show they were being kept. Edition 4.0 publishes the sequencing rule — wholeness before stability, stability before ascension — and attaches three gates with per-condition status. Gate 1 is open on written impartiality clearance, and while it is open Bawin issues no live reading to a paying customer. The nine refusals are published as a distinct list so they can be quoted in procurement without our consent.
Supersedes 2026-07-28-policy-v30
- 2026-08-12Security
The trust centre gains a Management system section: an information security management system structured to ISO/IEC 27001:2022 and an AI management system structured to ISO/IEC 42001:2023, with the Statement of Applicability summary (93 Annex A controls — 84 applicable, 5 applicable-inherited, 4 not applicable; 38 ISO/IEC 42001 Annex A controls) and the certification route with honest status. Structured to the standard is not certified to the standard: Bawin holds no certification to either, and cannot be certified by the certification body its director works for. That constraint is published rather than discovered. Each control in Security and disclosure now cites its Annex A reference so the list is traceable to the Statement of Applicability.
- 2026-08-12AI governance
What was found wrong: the trust centre stated both that no third-party model provider was in use and that model providers were contracted in writing to abstain from training on inputs and outputs. Both cannot be load-bearing. The second sentence is withdrawn. The published position is now single: no third-party model provider is in use, no customer evidence is sent to any external model, and if a provider is ever engaged it will appear in the sub-processor table with its establishment, processing region and training-abstention status, dated in this log before it is used.
- 2026-08-12Entity
The published contact address moves from a consumer free-tier mailbox to contact@bawin.co, a custom-domain mailbox on the same Swiss provider. The sovereignty position is unchanged; the address now matches the entity statement beneath it. /.well-known/security.txt is updated to match.
- 2026-08-12Release
Three invariant checks added to the served-output gate. A13: no published date on any served page is later than the build date of the artefact serving it, which catches a future-dated log entry automatically. A14: every document reference cited on a public page resolves to a published document with a matching edition and date, so no orphan reference can ship. A15: no served page describes Bawin as certified, accredited or approved. All three fail the build non-zero and are listed on the trust centre alongside A1 to A12.
- 2026-08-03Release
Release v2.7, published after a defect review of the served site. What was found wrong: Method §07 still denied a certification-body role that the trust log discloses; the trust log was being edited in place rather than appended to, and carried an entry dated 1 September 2026, ahead of the build; hallmark evidence dates were rendered in four different formats including an em dash; and the log itself lived inside a page component rather than in content. Fixed: the denial is withdrawn and the register renders from one record on Method §07 and Company Policy §06; the log moves to src/content/trustLog.ts as an append-only, date-descending structure with supersedes; the future-dated entry is redated to the day it shipped; hallmark dates render as full ISO only; and the invariant gate now fails the build on a denied-but-declared interest, a future-dated log entry, or a non-ISO hallmark date.
- 2026-08-03Independence
The certification-body interest, standing recusal, cross-issuance prohibition and unresolved impartiality clearance are published in the declared-interests register on Method §07 and Company Policy §06, from one registry record. The earlier statement that no officer held a role with a certification body is withdrawn as incorrect. No live readings have been issued.
Supersedes 2026-07-28-method-v21
- 2026-07-30Release
Release v2.6. The invariant gate now runs against deployed output only: the built site is served, every sitemap route crawled, every internal link and anchor followed, and the assertions made against fetched HTML. A second entity statement on the company policy page is removed, and the duplicate description of the checks on this page is deleted.
- 2026-07-30Release
Release v2.5 closed the stale-route deploy gap with served-output checks, rebuilt Method and Pricing, and aligned Ledger revenue arithmetic with the Value Bridge.
- 2026-07-30Entity
Registered office stated as 167–169 Great Portland Street, 5th Floor, London W1W 5PF, and rendered sitewide from one constant. The earlier locality was incorrect and is corrected here rather than quietly removed.
- 2026-07-28Method
Edition v2.1. Four factors: evidence freshness 40%, control coverage 35%, drift 15%, challenge resolution 10%. Comparability, mandated scope, overlap arithmetic and the Ledger translation are published as part of the method. Edition v2.0 is withdrawn and archived. No live readings were issued under an earlier edition.
- 2026-07-28Positioning
"Ratings agency", "credit score" and "credit bureau" removed sitewide. The Bawin Index is not a rating and is not comparable across companies; it is an index of the evidence you chose to connect, comparable to your own last reading. The load-bearing sentence is now published adjacent to every displayed number.
- 2026-07-28Site
The cull. /independence, /security, /privacy, /ai-governance and /changelog merged into this trust centre and permanently redirected to its anchors. /methodology redirected to /method. /frameworks redirected to /coverage. Framework counts removed from titles and headings.
- 2026-07-28Spine
Control spine published. One canonical, versioned control catalogue with every framework treated as a projection of it. Every mapping now states relationship (equivalent, subset, superset, intersects) and confidence (authoritative, derived, Bawin review) with a reviewer date.
- 2026-07-28Policy
Public company policy Edition v3.0 published at /policy, approved by the sole director of Bawin Limited, next review 28 July 2027.
- 2026-07-26Coverage
Coverage matrix moved to a four-state honest model (Mapped · In mapping · Committed · Not covered), with the reason stated for every framework we do not cover.
- 2026-07-22Entity
Bawin Limited incorporated in England and Wales, company number 17307761. Prior 'incorporation in progress' wording retired.
- 2026-07-10Privacy
Privacy notice rewritten to state the controller/processor split in full.
- 2026-07-01Security
Strict security headers enabled site-wide (HSTS, CSP, X-Frame-Options DENY, Permissions-Policy).