WerehouseMedia
Start a project
Services Industries Web design SEO AI search Automation Bespoke software AI receptionist Process FAQ Contact

Capability statement

The answers your procurement process needs.

The rest of this site is written for the person who will use the work. This page is written for the person who has to sign off on the supplier.

Werehouse Media is the trading name of Werehouse Holdings Ltd, a company registered in England and Wales, number 16802511. It is a one-person practice: Ed does the design, the build, the search work and the systems work. This page exists for buyers whose procurement or governance process needs more than a services page: larger organisations, charities, public-sector framework buyers and regulated firms. It sets out the accessibility standard the work is built to (WCAG 2.2 AA, with a published accessibility statement and known shortfalls listed rather than hidden), the security posture of what gets delivered, the data protection position under UK GDPR, the continuity and source code escrow answer that a single-person supplier has to be able to give, and which certifications are and are not currently held. Certifications not held are stated as not held. Two products sit on this page for buyers earlier in the process: an AI readiness assessment at £495, and process improvement consultancy scoped and quoted per engagement.

Send a due diligence request Certifications held

The supplier

Who you would be contracting with.

Trading nameWerehouse Media
Legal entityWerehouse Holdings Ltd
Registered inEngland and Wales, company number 16802511
Registered officePublished on the terms page
StructureOne person. No subcontracting of delivery without disclosure and agreement.
BasedEast Sussex. Clients across the United Kingdom, and remote engagements in Europe and the United States. Delivery is remote in every case, including UK work.
Contracting jurisdictionEngland and Wales. Overseas engagements are contracted on the same terms and invoiced in pounds sterling unless agreed otherwise in writing.
Concurrent capacityA small number of projects at once. Start dates typically two to three weeks out.

The capacity line is on this page deliberately. It is the single most common reason a larger organisation should choose somebody else, and finding it out at week six of a procurement helps nobody.

Accessibility

WCAG 2.2 AA, and a statement that names what falls short.

Accessibility appears contractually in most public-sector and third-sector procurement, and a surprising number of small suppliers cannot answer it. Everything built here targets WCAG 2.2 Level AA, and it is designed in rather than audited on afterwards. Retrofitted accessibility is more expensive and produces a worse result.

  • Semantic HTML, correct heading order, and a skip link on every page.
  • Keyboard operable throughout, with visible focus states that are not removed for aesthetics.
  • Contrast checked against AA thresholds for both body and interface text.
  • Motion respects prefers-reduced-motion, and no animation conveys information on its own.
  • Form fields with real labels, errors announced rather than only coloured.
  • Images carry meaningful alternative text, and decorative images are marked as decorative.

This site's own accessibility statement is the reference implementation: it names the standard, states the conformance level honestly, lists known shortfalls rather than omitting them, and gives a route to report a barrier. That is the shape the Public Sector Bodies Accessibility Regulations expect, and it is the shape produced for client sites.

Security posture

What is actually in place.

Described concretely rather than as a list of adjectives, using this site as the worked example, because it is the one you can verify yourself with browser developer tools before you speak to me.

  • HTTPS throughout, with HSTS set to two years including subdomains and preload-eligible.
  • A strict Content Security Policy. No inline script is permitted except two audited snippets allowed by cryptographic hash; no external script origins are allowed at all.
  • No third-party CDN, no third-party fonts, no analytics or advertising trackers. Loading a page discloses the visitor's IP address to the host and to nobody else.
  • Every browser capability denied by default through a fully enumerated Permissions Policy, rather than relying on defaults that can change.
  • Frame, MIME-sniffing and cross-origin protections set explicitly, and referrer information limited to the origin on cross-site requests.
  • Abuse protection on the enquiry endpoint that stores one-way hashes rather than identifiable data, for 24 hours and 15 minutes respectively.
  • Automated pre-flight checks gate every deployment, covering asset integrity, canonical correctness, structured data validity, form registration, redirect-loop detection and a scan for credentials accidentally committed.

Client work is built to the same posture. Where a client's existing stack cannot support part of it, that gap is written down at the start rather than discovered at a penetration test.

Certifications

Held, not held, and obtainable.

Stated plainly, because a supplier who is vague here is telling you something.

CredentialStatusDetail
Companies House registrationHeldWerehouse Holdings Ltd, 16802511, England and Wales.
WCAG 2.2 AAMet, and evidencedPublished accessibility statement with known shortfalls listed. Contractually committable.
UK GDPR complianceIn placeProcessor role, named sub-processors, published retention periods. See below.
Cyber EssentialsNot currently heldObtainable within a normal procurement timeline where a contract requires it. Commitment given in writing.
ISO 27001Not heldDesigned around organisations with staff. If it is a hard gate for you, a larger supplier is the right answer.
Source code escrowAvailable on requestArranged with a third-party agent and written into the contract for engagements where it matters.
InsuranceArranged per engagementCertificates provided on request during due diligence. Tell me the levels your process requires.

Two of those rows say "not held", which is the point of publishing the table. A capability statement that lists only what a supplier has is a marketing document; one that lists what it does not have is a document you can make a decision from.

Data protection

Controller, processor and who else touches it.

Where personal data is handled on a client's behalf, Werehouse Media acts as processor and the client as controller under UK GDPR, and that is written into the terms of business rather than assumed. A data processing agreement can be executed as part of contracting.

For this website, the sub-processors are named individually in the privacy policy rather than described as "trusted partners": the host, the transactional email provider, and the mailbox provider. Retention periods are published for each category of data. There is no mailing list, no data is sold or shared for marketing, and there are no advertising or analytics trackers to disclose.

For client systems, the equivalent list is produced during the build and handed over with the documentation, so the client can answer their own customers' subject access requests without asking me who holds what.

Continuity

The single-supplier question, answered properly.

The risk in commissioning a one-person practice is real and it is concentrated in one place: what happens if that person becomes unavailable. Four things reduce it, and they are all structural rather than promises.

  • Nothing proprietary. Mainstream, documented technology throughout. No framework invented here, no build tool only I understand.
  • Accounts in your name. Hosting, domain, vendor subscriptions, and every third-party service. Access never routes through me, so losing me does not lose you anything.
  • Handover at completion, not on exit. Source code and written documentation are delivered as part of the build rather than held as leverage.
  • Escrow where it is warranted. A third-party escrow agreement for larger systems, so the code is releasable to you on defined trigger events.

The mirror image is worth stating too: the reason to choose a practice this size is that the person evaluated is the person who does the work, there is no account layer between the brief and the build, and there is nobody to hand your project to when a bigger client arrives.

For larger organisations

Two ways to start without committing to a build.

AI readiness assessment: £495

A written assessment of whether an organisation can usefully use AI, and where. What data exists and what state it is in. Which processes are genuine candidates and which are not. What governance and human oversight each would need, which is increasingly the part that decides whether a project is allowed rather than whether it works. Realistic cost and payback. And what should be left alone.

It regularly concludes that the highest-return work is ordinary automation, or a data-quality problem, rather than anything involving a model at all. A vendor whose product is AI cannot comfortably reach that conclusion, which is most of the reason to buy the assessment from somebody who does not sell one.

Process improvement consultancy: scoped per engagement

The same discipline applied without the technology framing: where the operational time actually goes, which steps exist because of a decision nobody remembers making, what would change if two systems agreed with each other, and what the realistic operational efficiency gain is. The output is a written document with costed options, not a slide deck.

Both connect to the delivery side of the practice: bespoke software and CRM for systems with their own data model, business automation for the workflow layer, and document and enquiry automation for contract, proposal and onboarding work. Data integration between systems that were never designed to speak to each other is usually where the first genuine win sits.

Due diligence

Common questions.

Not currently, and it would be easy to be vague about that. Cyber Essentials is a realistic and worthwhile certification for a practice this size and is the one most commonly written into UK public-sector and larger corporate contracts; where a contract requires it, it can be obtained inside the procurement timeline and that commitment will be given in writing. ISO 27001 is a management-system certification designed around organisations with staff, and for a one-person practice it would be an expensive piece of paper describing controls that a single operator implements differently. If a buyer's process treats ISO 27001 as a hard gate, that is a legitimate reason to choose a larger supplier, and I would say so rather than waste your evaluation time.

The honest bus-factor answer, because a single-person supplier who dodges this question should not be shortlisted. Everything is built on mainstream documented technology rather than anything proprietary. Every account is in the client's name, so access never depends on mine. Source code and written documentation are handed over at completion rather than held back. For engagements where it matters, a source code escrow arrangement with a third-party agent can be written into the contract. And the practical answer for smaller work: a competent developer can pick up a documented, mainstream codebase in days, which is exactly why it is built that way.

Cover appropriate to the engagement is arranged before contracts are signed, and the certificate is provided on request as part of due diligence rather than published on a web page. If your procurement process specifies particular levels of professional indemnity or public liability cover, tell me the figures at the enquiry stage; it is a straightforward thing to confirm or to decline honestly if the level required is disproportionate to the work.

Yes, and it is worth checking that any supplier saying yes can show you a site that does it. This site publishes an accessibility statement that names its target standard and lists what is known to fall short, which is the form the Public Sector Bodies Accessibility Regulations expect and which most small suppliers cannot produce. Accessibility is built in during design rather than audited on at the end, because retrofitting it is both more expensive and worse.

Yes, with a caveat worth stating early. The practice has capacity for a small number of concurrent projects, so a framework engagement with a large concurrent volume is not a good fit and I would rather say that at the first conversation than at the delivery stage. For discrete, well-scoped pieces of work (a website, an accessibility remediation, a system integration, a search visibility programme) the size of the supplier is an advantage rather than a risk, because the person you evaluate is the person who does the work.

A written assessment of whether an organisation is in a position to use AI usefully, and where. It covers what data exists and what state it is in, which processes are candidates and which are not, what governance and human oversight each candidate would need, what the realistic cost and payback look like, and what should be left alone. It is £495 and is credited in full against any resulting build over £2,000. It frequently concludes that the highest-return work is ordinary automation or a data-quality problem rather than anything involving a model, which is a conclusion a vendor selling AI cannot easily reach.

Next step

Send me the questionnaire.

If your process has a supplier questionnaire, a security schedule or a set of insurance thresholds, send it over and you will get it back completed, including the questions where the answer is no.

Start due diligence Third-sector work