Security & Compliance

We secure your code the way we secure ours.

Reviewed releases, least-privilege access, and encryption in transit and at rest - by default, on every engagement.

Controls

Security by default, not a tier.

The controls that run on every engagement. The full security overview is available to your team on request.

SOC 2-aligned controls
Encrypted in transit & at rest
Least-privilege access
NDA-first engagement
Reviewed releases
Dependency scanning on every build
Request the full security overview →

In detail

What each control actually means.

Compliance & certifications

SOC 2-aligned controls
We build to the control objectives behind SOC 2. Certification is not complete - if your process requires a report, say so early and we will tell you where we stand.
Named engineers, under NDA
Everyone on your project is named to you and under NDA before they get access, and the person who writes a change answers for it.
GDPR & CCPA alignment
Lawful basis for processing, access and deletion requests honored, and collection limited to what the work needs.
NDA-first engagement
A mutual NDA is signed before we see your code or roadmap. Confidentiality is the precondition, not the afterthought.

Data & privacy

Encryption in transit and at rest
TLS 1.2+ in transit, AES-256 at rest on managed infrastructure. Keys are held by the platform provider, not in application code.
Data residency & retention
We deploy to the region you specify and keep data only as long as the work requires. Returned or destroyed on your instruction at close.
Code & IP ownership
You own the work product. Rights are assigned to you in writing on payment - we keep nothing and reuse nothing.

Secure engineering

Secure SDLC
Reviewed pull requests, protected branches, and required CI checks. Nothing merges without review and a green pipeline.
Least-privilege access
Minimum access per task, scoped per project and revoked the day an engineer rolls off. Where you offer them, we work inside your access grants rather than our own.
Dependency & vulnerability scanning
Dependencies and container images are scanned on every build. Known-critical vulnerabilities block the release.

Operations & response

Independent testing, per engagement
Where an engagement calls for independent penetration testing, we bring in a third-party tester and remediate what it finds before release.
Incident response & disclosure
If an incident affects your data, you hear it from us in writing - what happened, what we have done, and what we are still checking. Severities and notification windows are set in your contract.
Monitoring where we operate
Systems we run in production are monitored for availability and errors, with alerts routed to the engineer on the engagement. Out-of-hours cover is agreed per engagement and scoped to what your system actually needs.

Documentation

What you can ask for.

Where each document stands today, so your review knows what to expect before it asks.

Security overview

Public

How we handle code, data, and access - this page, in brief.

Mutual NDA

Before kickoff

Signed before we see your code or roadmap - yours or ours, whichever you prefer.

Data processing agreement (DPA)

On request

How we process personal data on your behalf, with standard contractual clauses where a transfer needs them.

Who touches your project

Per engagement

The providers and the named engineers with access, given before we start and updated if either changes.

SOC 2 Type II report

Not yet

Certification is not complete. If your process requires a report, raise it at first contact and we will tell you where we stand.

Third-party test report

Per engagement

Where an engagement commissions an independent test, the tester's report goes to you in full.

What we build on

A stack you can vet.

The infrastructure and tools that may handle data on your project - audited providers your security team likely already approves.

Amazon Web Services

Hosting, storage, content delivery (CloudFront), DNS, and transactional email

US / EU (per project)

GitHub

Source control, review, and CI - where we host the repository rather than working inside yours

US

Google Workspace

Email and documents - where correspondence about your project lives

US

The providers that would touch your project. Anything else is named in your agreement before it is used.

Security is part of how we build, not a tier you upgrade into.

Built to ship. Built to last.

Start a project →