Skip to content
Security & data handling

The answers your security team will ask for

How we handle access, data, infrastructure and incidents across engagements. Engagement-specific terms are formalised in the data processing agreement signed per engagement.

Access & accounts

Least privilege
Engineers get the minimum access the milestone requires, granted per person, revoked at engagement end — with an access log you can audit.
Your environment, your rules
We work inside your cloud accounts and identity provider where possible. VPN-only access, managed devices and background checks are supported where required.
MFA everywhere
Multi-factor authentication is mandatory on all accounts we operate — ours and the ones you grant us.
Secrets management
Credentials live in a secrets manager, never in code, chat or documents. Rotation on handover is standard.

Data handling

Data minimisation by default

Development and testing run on synthetic or anonymised data wherever feasible. Production data access is the exception, logged and justified.

GDPR-aligned engineering

Retention policies, deletion flows and consent handling are designed into systems from the first milestone — not retrofitted before launch.

AI-specific safeguards

No training on your data without written consent. Model deployment options range from EU-hosted APIs to fully self-hosted open weights, chosen per data sensitivity.

Residency options

EU-only hosting and processing available across the stack when your compliance posture requires it.

Secure engineering practice

Review & CI gates

Every change is peer-reviewed; dependency and vulnerability scanning run in CI on every build.

Encrypted everywhere

TLS in transit, encryption at rest, and infrastructure defined as code so the security posture is reviewable, not tribal.

Audit trails

Systems we build log who did what, when — including automated actions and AI decisions, queryable by your team.

Incidents & continuity

Systems fail; what matters is how they fail and how fast you know. Every system we operate ships with this posture:

Monitoring & alerting from day oneAlerts route to your channels and ours simultaneously
Defined incident responseNamed contacts, severity levels and notification windows agreed per engagement
Tested backupsBackup and restore procedures verified, not assumed — restore drills on operate retainers
Honest post-mortemsWritten, blameless, shared with you — including what we got wrong

Security questionnaire to fill?

Send it over — we answer vendor assessments as part of the estimate phase.

Contact us