Security & Compliance
We secure your code the way we secure ours.
Reviewed releases, least-privilege access, and encryption in transit and at rest - by default, on every engagement.
Controls
Security by default, not a tier.
The controls that run on every engagement. The full security overview is available to your team on request.
In detail
What each control actually means.
Compliance & certifications
- SOC 2-aligned controls
- We build to the control objectives behind SOC 2. Certification is not complete - if your process requires a report, say so early and we will tell you where we stand.
- Named engineers, under NDA
- Everyone on your project is named to you and under NDA before they get access, and the person who writes a change answers for it.
- GDPR & CCPA alignment
- Lawful basis for processing, access and deletion requests honored, and collection limited to what the work needs.
- NDA-first engagement
- A mutual NDA is signed before we see your code or roadmap. Confidentiality is the precondition, not the afterthought.
Data & privacy
- Encryption in transit and at rest
- TLS 1.2+ in transit, AES-256 at rest on managed infrastructure. Keys are held by the platform provider, not in application code.
- Data residency & retention
- We deploy to the region you specify and keep data only as long as the work requires. Returned or destroyed on your instruction at close.
- Code & IP ownership
- You own the work product. Rights are assigned to you in writing on payment - we keep nothing and reuse nothing.
Secure engineering
- Secure SDLC
- Reviewed pull requests, protected branches, and required CI checks. Nothing merges without review and a green pipeline.
- Least-privilege access
- Minimum access per task, scoped per project and revoked the day an engineer rolls off. Where you offer them, we work inside your access grants rather than our own.
- Dependency & vulnerability scanning
- Dependencies and container images are scanned on every build. Known-critical vulnerabilities block the release.
Operations & response
- Independent testing, per engagement
- Where an engagement calls for independent penetration testing, we bring in a third-party tester and remediate what it finds before release.
- Incident response & disclosure
- If an incident affects your data, you hear it from us in writing - what happened, what we have done, and what we are still checking. Severities and notification windows are set in your contract.
- Monitoring where we operate
- Systems we run in production are monitored for availability and errors, with alerts routed to the engineer on the engagement. Out-of-hours cover is agreed per engagement and scoped to what your system actually needs.
Documentation
What you can ask for.
Where each document stands today, so your review knows what to expect before it asks.
Security overview
Public
How we handle code, data, and access - this page, in brief.
Mutual NDA
Before kickoff
Signed before we see your code or roadmap - yours or ours, whichever you prefer.
Data processing agreement (DPA)
On request
How we process personal data on your behalf, with standard contractual clauses where a transfer needs them.
Who touches your project
Per engagement
The providers and the named engineers with access, given before we start and updated if either changes.
SOC 2 Type II report
Not yet
Certification is not complete. If your process requires a report, raise it at first contact and we will tell you where we stand.
Third-party test report
Per engagement
Where an engagement commissions an independent test, the tester's report goes to you in full.
What we build on
A stack you can vet.
The infrastructure and tools that may handle data on your project - audited providers your security team likely already approves.
Amazon Web Services
Hosting, storage, content delivery (CloudFront), DNS, and transactional email
US / EU (per project)
GitHub
Source control, review, and CI - where we host the repository rather than working inside yours
US
Google Workspace
Email and documents - where correspondence about your project lives
US
The providers that would touch your project. Anything else is named in your agreement before it is used.
Security is part of how we build, not a tier you upgrade into.
Built to ship. Built to last.