SW Digital Services

Software and information security · Hull, East Yorkshire

Practical software and information security for UK businesses.

SW Digital Services makes ClearIMS, helps organisations put ISO 27001 in place and keep it running, and builds bespoke web software that is secure from the first line. You deal directly with the person doing the work.

Services

Three ways we can help

Software that does the work, advice that gets you certified on your own terms, and code you can rely on.

ClearIMS (formerly AI-27001)

ISO 27001 software that drafts your ISMS and keeps it running.

  • Drafts your scope, risk register, Statement of Applicability and policies from a plain-English description of your business.
  • Works like a virtual ISMS manager: it chases outstanding actions by email and updates them from people’s replies.
  • The AI drafts; a named person in your organisation approves. Nothing is approved without them.
Visit clearims.com

ISO 27001 consulting

Hands-on help to scope, build and run an ISMS and prepare for certification, done alongside your people.

  • Scope, context and interested parties agreed in a workshop, not guessed.
  • Risk assessment, risk treatment and a Statement of Applicability against ISO/IEC 27001:2022 Annex A.
  • Policies written for how you actually work, owned by the people who will run them.
  • Internal audit and management review set up, and preparation for stage 1 and stage 2.

Certification is awarded by an accredited certification body. We help you prepare; we never certify anyone or guarantee the result.

Discuss your ISMS

Software development

Bespoke web apps and integrations, built securely and documented for handover.

  • Internal tools and customer portals that replace spreadsheets and email chains.
  • Integrations that connect the systems you already pay for through their APIs.
  • Widely used, well-supported tools such as TypeScript, React and Node.js, so another developer can pick the work up.
Describe what you need

How we work

Recognised good practice, applied to every job

The same habits on a two-week integration as on a long-running platform. They follow published UK and international guidance rather than house rules.

  1. Security by design

    Threats and data flows are mapped before code is written. Secure defaults from the start: least privilege, encrypted connections, input validation and secrets kept out of the code, checked against OWASP ASVS.

  2. Code review

    Every change goes in through a pull request with a written description, a security checklist and automated checks. If your team wants to review changes too, they can.

  3. Automated testing

    Unit and integration tests run on every change. When a bug turns up, the fix comes with a test that reproduces it, so it stays fixed.

  4. CI/CD

    Builds, tests, linting and dependency vulnerability checks run automatically. Releases are small, frequent and easy to roll back, and nothing reaches production without passing.

  5. Documentation and handover

    A README that gets a new developer running, notes on the architecture and the decisions behind it, and a runbook for deploying and recovering. Written so someone else can take over.

  6. Accessibility

    Interfaces built to WCAG 2.2 level AA: full keyboard access, visible focus, readable contrast, proper form labels and error messages, and checks with a screen reader.

  7. Data protection

    Data protection by design and by default, as UK GDPR requires. Collect only what is needed, keep it only as long as it is needed, limit who can see it, and support a DPIA where the processing calls for one.

  8. Plain-English communication

    A short written update every week: what is done, what is next, and anything that needs a decision from you. No jargon, and no surprises.

  9. Fixed scope or monthly

    A fixed price for well-defined work, or a monthly arrangement for ongoing development, support or running your ISMS. Either way, you agree the cost before work starts.

About

A small company, on purpose

SW Digital Services was founded by Sam Wilkinson to give UK businesses straightforward help with two things that are easy to get wrong: information security and the software that runs the business.

The company makes ClearIMS, so the consulting and the software come from the same working knowledge of ISO 27001: what the standard asks for, what an auditor will want to see, and what a small team can realistically keep running after the audit.

Work is done directly with you, not passed down a chain. Sam can meet in person across Hull and East Yorkshire, and works remotely with businesses anywhere in the UK.

Founder
Sam Wilkinson
Based in
Hull, East Yorkshire
Company
SW Digital Services Limited
Registered
England and Wales, company no. 17178287

Contact

Start a conversation

A few lines is enough: what you are trying to do, and any deadline. You will get a reply from Sam personally, not an automated sequence.