MEMON SYSTEMS

trust

Where client data goes, who holds access to it, and how each claim below is verified.

This page covers client data in engagements. The privacy policy covers visitors to this website.

1. Jurisdiction and contracting structure

The contracting entity is Memon Systems Ltd, Company No. 17284215, registered in England & Wales. Engagements are governed by English law and the exclusive jurisdiction of the English courts (MSA clause 20.12).

All work is delivered by Abdullah Memon, resident in Pakistan. Professional indemnity and cyber liability cover is placed with UK underwriters, with worldwide territorial limits (including work performed in Pakistan; excluding USA and Canada) and jurisdiction covering English courts.

Delivery model: Separation of Duties

Client personnel hold all production credentials. Architecture is delivered as Infrastructure-as-Code and deployed by your engineers or CI/CD pipelines. No production data is transferred, hosted, or accessed remotely. Development and benchmarking execute exclusively against synthetic or structure-preserving masked corpora.

Procurement instruments

For enterprise vendor onboarding compliance, Memon Systems Ltd executes a Data Processing Agreement (DPA) alongside the UK International Data Transfer Agreement (IDTA / UK Addendum to EU SCCs) and Transfer Risk Assessment (TRA).

2. Zero data access

Memon Systems hosts no client infrastructure. Systems are deployed directly into your cloud tenancy. No client production data leaves your environment or is replicated off-tenancy.

Operational troubleshooting is conducted exclusively through supervised screen-shares with your engineers or temporary break-glass access under named client approval with session recording. Credentials are not stored or retained outside these sessions.

Handover (Architecture Build & Remediation tiers)

For Compliance Architecture Build and Remediation Specification engagements, comprehensive documentation accompanies delivery: architectural specifications, data flow diagrams, Infrastructure-as-Code modules, and operational runbooks. Your engineering team receives structured walkthroughs until independent operational ownership is established.

The standalone Deployment Audit engagement delivers an external findings and measurement report; no infrastructure or runbooks are transferred.

Telemetry and monitoring

Telemetry emitted by deployed architectures contains zero personal data or client matter identifiers. Ingestion and evaluation pipelines execute structure-preserving masking over diagnostic fields. Retrieval drift is baselined against public statutory corpora, enabling continuous quality tracking without exposing client documents.

Deployment Audit intake

Commissioning the £500 Deployment Audit requires four inputs: system operational scope, practice areas covered, probe operator identity, and domain authorization. Intake and payment processing are managed via Stripe; no proprietary codebases, credentials, or internal documents are requested or retained.

3. No sub-processors

Memon Systems engages no sub-processors. All architectural audits, code authoring, and advisory deliverables are executed directly by Abdullah Memon.

No third-party contractors or external processing entities are utilized in the delivery of client work.

4. Verifiable artefacts

Corporate credentials, statutory registrations, insurance limits, and governance framework crosswalks.

Artefact Detail and status
UK company Memon Systems Ltd, Company No. 17284215, England & Wales. Registered office: 60 Tottenham Court Road, Office 1418, Fitzrovia, London, W1T 2EW.
ICO registration Reference ZC208663, searchable on the ICO's public register of fee payers. Tier 1. Assessed as not exempt under the self-assessment, and paid.
GPG-signed commits Ed25519, valid to July 2028. A487 3AE7 AEE6 56BF F54E C751 B5C9 93EA B678 58DE Public key · fingerprint also published on /about as a second source.
Police Character Certificate Official Police Character Certificate issued by SSP Hyderabad, Pakistan (jurisdiction of residence), verified and apostilled under the Hague Convention.
Professional indemnity £2,000,000 any one claim, unlimited in the aggregate. Nil excess. Retroactive cover unlimited. Dishonest or malicious acts are excluded.
Cyber liability £100,000 total limit in any period of insurance, with individual sections between £20,000 and £100,000 and a £100 excess per claim. A distinct limit from the professional indemnity cover above, covering distinct claims. The two are not combined.
Other cover Public liability £1,000,000 · products liability £1,000,000 · employers' liability £10,000,000. The employers' liability limit is included in the policy as standard. The company has no employees and is not taking any on; it is the same fact as §3.
Territorial and jurisdiction limits Territorial limit — where the work may be performed: worldwide, excluding the USA and Canada. Jurisdiction limit — where a claim may be brought: any court, excluding US and Canadian courts. English courts are within limits.
No cookies, no analytics This website loads no third-party asset and sets no cookie. Stated in full in the privacy policy, and reproducible in a browser network panel.
IDTA · Transfer Risk Assessment Signed as a backstop instrument. Grants no access.
CAIQ · SIG Lite · NIST AI RMF and ISO 42001 crosswalks Control sets designed against (NIST AI RMF 1.0, ISO/IEC 42001:2023, ISO 27001, CSA CAIQ v4), with audit evidence produced for client procurement.

5. Confidentiality and publication boundaries

  • Strict publication control: No client architecture, system benchmark, or operational telemetry is published or referenced without prior written consent.
  • Pre-engagement confidentiality: Information shared during scoping calls or diagnostic intake remains confidential under NDA, whether or not an engagement proceeds.
  • Public research isolation: Published case studies and research harnesses execute exclusively against public statutory corpora and synthetic benchmarks. Client data—anonymized or otherwise—is never utilized for public material.

The diagnostic runs entirely under the no-access model.

What this costs