Your privacy is important. Our Cookies Statement explains how we use cookies on this site. You can change their use at any time, deciding between the strictly essential and those that are just optional. You accept them by continuing to use this site. Our Privacy Statement explains how we use and protect your data.
Switchboard
+44 (0)1392 259797
Service Desk
+44 (0)1392 286500
Direct Access
+44 (0)3304 010030

Security

Revell Research Systems takes information security seriously. We have established a robust framework of governance, management and technical controls designed to protect our information assets, systems, services, staff, associates and stakeholders.

This website uses HTTPS to encrypt communications between your web browser and our systems. This helps protect information exchanged online from interception, alteration or unauthorised disclosure whilst in transit.

Information about how we collect, use, disclose, retain and protect personal information can be found within our privacy section.

We set out below the security measures that we have implemented to help protect information when interacting with us. We review these measures periodically as part of our commitment to continuous improvement. Whilst specific controls may evolve over time, our objective remains to maintain an appropriate level of security for the services we provide.

If you have any comments regarding the security of this website, please contact us at security@rrs.co.uk.

Revell Research Systems operates an Information Security Policy Framework that sets out how we manage our information security. We also have formal policies that cover risk management across the business.

Our policies are approved by the Board of Directors and are all formally reviewed at least annually.

We communicate these policies internally to all our staff and associates and actively monitor compliance.

We train those working for us and regularly check security behaviour across the business. We conduct annual training, which starts when anyone joins us to ensure everyone knows their responsibilities.

Our Service Desk operates a robust security incident management process that is designed to quickly investigate and respond to security incidents.

Security incidents are managed through documented procedures designed to support detection, investigation, containment, recovery and continual improvement.

We will inform you if your personally identifiable information is impacted by a data breach and provide you with details of the incident, where appropriate.

We maintain asset registers for data repositories, devices, systems and software so we know exactly what we must protect and what is at stake.

In particular, we carefully track where personally identifiable information is stored and used across our information assets.

We conduct regular information risk assessments to identify risks and to assess the likelihood and impact of them materialising. We take active steps to mitigate these information security risks so that we can maintain the confidentiality, integrity and availability of our information assets.

The status of our information security risks is regularly reported to the Board of Directors and senior management.

We control our IT systems carefully. We patch our systems regularly to remove known vulnerabilities and reduce the threat to them. We implement careful change control to minimise the risks associated with updates to our IT systems, data and business.

We carefully select and manage the hosting environments and service providers that support our systems and services. We seek to ensure that appropriate technical, organisational and contractual safeguards are in place to protect information and maintain the confidentiality, integrity and availability of our systems and data.

We carefully control access to our premises and ensure appropriate levels of physical security, monitoring and detection are in place. We regularly test our intruder detection and fire alarm measures.

Visitor access to our premises is controlled. Visitors are accompanied at all times.

We position our equipment within our premises to minimise the visibility of confidential information and instruct staff and associates to take particular care of mobile devices such as laptops, tablets and phones when they are being used in public spaces.

We require staff and associates to obtain permission from asset owners prior to removing equipment from our premises. We also instruct them to keep mobile equipment secure at all times and to be vigilant about the inherent risks of using mobile equipment outside of the office.

We use encryption where appropriate to protect sensitive information, particularly when information is stored on mobile devices or transmitted electronically.

We record all physical hardware assets in asset registers. These are kept up-to-date by asset owners, who are responsible for ensuring the accuracy of the information stored about each asset.

We require staff and associates to operate a clear desk policy and lock any confidential information away when not at their desks.

We also require our staff and associates to lock their systems when they are away from them.

We exercise careful access control to prevent unauthorised people from gaining access to our systems to ensure that data cannot be read, copied, altered or removed without authorisation. This includes any personal data that we may process.

We only grant the minimum permissions needed to staff and associates for them to perform their work.

We audit and actively monitor access to information assets.

We also control access to software development environments and ensure that only staff and associates who need access to them are authorised to do so.

We require the use of unique user credentials and strong passwords when using our systems. We use multi-factor authentication (MFA) to protect critical systems to minimise the potential for unauthorised access.

We store user credentials in highly secure password management systems that audit access and use of credentials.

We protect our systems with anti-virus software and anti-malware tools that are configured to automatically update, monitor and scan for threats. We enforce their use on servers and all user devices. We scan all files and email content crossing our system boundaries, quarantining or deleting items as appropriate.

We also use an anti-spam system that blocks or quarantines suspicious email.

We implement a sophisticated firewall solution that blocks unwanted ingress traffic and protects against unexpected egress traffic as well as inspecting content, where appropriate.

We also operate intrusion detection systems and actively monitor hosts trying to connect to our systems. We actively monitor and log network activity.

We regularly scan our systems for known vulnerabilities and conduct routine testing of our security measures.

We periodically commission external tests of our defences to ensure we maintain appropriate and effective security controls.

Revell Research Systems welcomes reports of suspected security vulnerabilities affecting our websites, systems and services.

Security concerns and vulnerability reports should be submitted to security@rrs.co.uk. Reports should provide sufficient information to enable us to understand, reproduce and investigate the issue.

We review and investigate all credible reports, as appropriate. We request that vulnerabilities are disclosed responsibly and that sufficient time is allowed for investigation and, where necessary, remediation before any public disclosure.

Information about reporting security concerns is also available through our security.txt file.

We have emergency and business continuity plans in place to help overcome any unexpected incidents at our premises, to key personnel or to any important systems that we rely on for day-to-day operations. The plans are designed to enable us to resume activities whether the situation is one of full or partial loss of key assets.

We make all our staff and associates aware of the plan in their induction and subsequent refresher training. If there are any significant changes to the plan, we communicate these changes to them.

We are registered with the Information Commissioner's Office (ICO) under Notification Number Z186392X.

We seek alignment with recognised standards and good practice frameworks where appropriate and periodically evaluate opportunities for independent accreditation. Our information security framework is informed by recognised industry good practice, including guidance published by the National Cyber Security Centre (NCSC), risk-based security management principles and continuous improvement practices.

8th September 2026 (Reviewed: 13th September 2026).

Keep Informed

Responsible for digital technology in your business?

Subscribe

Learn More

Revell Research Systems is a management and technology consulting firm, practising as Chartered IT Professionals and Chartered Engineers.

You might want to explore our main website to find out more about us.

We are independent and impartial. We do not sell third party products or services.

Contact Us

9-11 Coates Road
Exeter
Devon
EX2 5RH
United Kingdom

Tel:
+44 (0)3336 000032
Fax:
+44 (0)1392 499691
EMail:
office@rrs.co.uk

Download our contact details for future reference as a vCard.

Download our brochure to share and understand our proposition to your business.

Download Brochure

Revell Research Systems Limited is a private limited company registered in England and Wales under Registration Number 06939580 with its registered office at 5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom. Its VAT Number is GB 922 4578 19.

Copyright © 2026 Revell Research Systems Limited. All rights reserved.

Software Developed in Exeter by Revell Research Systems