Skip to content
BastionSec
Contact us
Data Protection

Protect the data that matters: access, encryption, leak prevention.

A single hub to secure your company's information: who can access what, how it's encrypted, how you stop it leaking by mistake. Practical, tailored to your stack, no needless bureaucracy.

  • Access management and least privilege: each person sees only what they need.
  • DLP and classification: sensitive data is labelled and won't leave by mistake.
  • Encryption and governance across Google Workspace/M365 and 1Password.

Who data protection is for

Quick self-qualification: do you recognise yourself in one of these?

SMB with no security team

Data scattered across shared Drives, email and a dozen tools: nobody really knows who accesses what. We bring order.

Company in compliance

You're preparing ISO 27001 or GDPR and need real controls over access, encryption and data handling.

See ISO 27001

Anyone handling third-party data

You process client or user data and must show you protect it: classification, access control and leak prevention.

See GDPR

What data protection is (and what we mean by it)

Data protection here means protecting your company's information across its whole lifecycle: knowing what data you hold and how sensitive it is, controlling who can access it, encrypting it at rest and in transit, and stopping it from leaking by mistake or attack.

It isn't a single product: it's a coordinated set of controls over people, data and the tools you already use (Google Workspace or Microsoft 365, password manager, cloud storage). We put them in place pragmatically, starting from the real risks.

Data protection is also part of GDPR and ISO 27001 (Annex A: access control, cryptography, classification). If you're on a certification path, this is where you build concrete evidence.

What's included

The pillars we work on. Some have a dedicated page.

Access management (IAM)

Centralised identity, SSO/MFA, least privilege and periodic access reviews. Clean onboarding and offboarding.

Workspace & Identity

DLP: data leak prevention

Rules to stop sensitive data leaving via email, sharing or unauthorised downloads.

Encryption

Encrypting data at rest and in transit, key and secret management, encrypted disks on devices.

Data classification

We label data by sensitivity (public, internal, confidential) so protection rules follow the data.

Workspace/M365 governance

Hardening Google Workspace or Microsoft 365: sharing, permissions, retention, log auditing.

Learn more

1Password: secrets management

Company password manager: team vaults, secure sharing, no more passwords in spreadsheets.

How it works

A staged method. AI speeds up the repetitive part (inventory, first-pass analysis, policy drafts); people do the analysis and validate. Your data stays protected: it's our day job.

  1. 1

    Discovery & inventory

    We map existing data, tools and access.

  2. 2

    Classification & risk

    We label data and surface the priority risks.

  3. 3

    Control design

    Access, DLP, encryption and governance tailored to your stack.

  4. 4

    Implementation

    We configure Workspace/M365 and 1Password.

  5. 5

    Verification & monitoring

    We check the rules work and keep an eye on access.

Standards and methods

  • Least privilege and separation of duties (RBAC).
  • Controls mapped to ISO/IEC 27001 Annex A (access, cryptography, classification).
  • Alignment with GDPR principles on data minimisation and protection.
  • MFA and SSO (SAML/OIDC) for application access.
  • Encryption of data at rest and in transit following good practice.

Model and pricing

Data protection is partly a project (initial setup: classification, DLP rules, hardening) and partly ongoing management (access reviews, rule maintenance, monitoring).

For setup we give a 'from' price pinned down after the initial assessment; the managed part is a subscription, sized on number of users and complexity. See the pricing page for the ranges.

Frequently asked

Is data protection the same as GDPR?

No. GDPR is a regulation on personal data protection; the data protection we mean here is the set of technical and organisational controls (access, DLP, encryption, classification) that protect data. These controls also help you comply with GDPR, but they don't cover all of it.

Does it work with our current tools?

Yes. We work on the stack you already use: Google Workspace or Microsoft 365, 1Password, your cloud storage, without forcing you to replace everything. Where useful, we suggest targeted additions.

What is data classification and why does it matter?

It's labelling data by sensitivity (public, internal, confidential). It matters because protection rules (who accesses, what can leave, how it's encrypted) can then automatically follow the data's level, instead of treating everything the same way.

Does DLP block everything and slow people down?

A well-configured DLP protects without getting in the way: rules target real risk (sensitive data leaving where it shouldn't), not day-to-day work. We tune it together starting from your workflows.

Do you have a page on removing metadata from documents?

Yes. Removing hidden metadata in files (author, revisions, GPS) is a dedicated service. It's useful before sharing documents externally, but it's a different thing from GDPR anonymisation.

Go deeper

Metadata scrubbing

Removing hidden metadata from documents before sharing them externally. A dedicated service.

Learn more

Managed Workspace & Identity

Hardening of Google Workspace/M365, IAM, SSO/MFA and 1Password. The heart of access management.

Learn more

GDPR

What GDPR requires and how data protection contributes to compliance. Informational.

Read the guide

Find out where your data is at risk.

Tell us your need: we map access and sensitive data and tell you where to start, honestly.