Skip to content

Security & Compliance

This page exists so your procurement and security teams can get answers without waiting on an email thread. If a line here is not detailed enough for your questionnaire, ask — we would rather answer now than at contract stage.

Data protection

  • Where data lives. Client data stays in the client’s own environment and chosen region. We build and test against sanitised or synthetic data unless you explicitly provide otherwise.
  • GDPR and local law. We sign your data-processing agreement, or provide ours. Processing terms follow the jurisdiction you nominate in the contract.
  • Retention and deletion. Project material is removed from our systems on request at the end of an engagement, and a written confirmation is provided.
  • Sub-processors. Any third party that would touch your data — hosting, email, analytics, AI tooling — is listed in the statement of work before it is used. None is introduced mid-project without notice.

Certifications and assurance

We share our current certification and independent-audit status in writing during procurement, so that what you rely on is a dated document rather than a web page. Penetration-test summaries for work we have delivered can be shared under NDA with the client’s consent.

How we work securely

  • Access. Named accounts only, multi-factor authentication on the tools that hold client work, least-privilege by default, and access revoked on the day someone leaves a project.
  • Devices. Client work is done on company-managed machines with full-disk encryption and automatic screen-lock.
  • Code. Private repositories, review before merge, dependency scanning, and secrets kept out of source control — always in a vault or environment configuration.
  • Environments. Production, staging and development are kept separate. Client production credentials are never copied into development.
  • People. Engineers with access to client systems are identity-verified; enhanced background screening is arranged where your policy requires it.

Contracts and commercial

  • NDA. We sign yours, or provide ours — whichever your legal team prefers.
  • MSA / SOW. We work under our standard master agreement or under the client’s paper.
  • IP ownership. Deliverables and their source code are assigned to you on final payment. Pre-existing tooling we bring is identified in the SOW and licensed to you for the deliverable.
  • Insurance and escrow. Professional-indemnity cover and source-code escrow arrangements are provided on request and agreed per engagement.

Availability and support

  • Coverage. Nine locations across Asia, the Middle East, Europe, the Americas and Australia give near-continuous coverage across business days.
  • Response targets. Set per engagement and written into the SOW, with severity tiers you can hold us to.
  • Escalation. Every engagement has a named delivery lead and a named escalation contact above them, both in the SOW.
  • Continuity. No client depends on a single engineer: work is documented in the repository and at least one other engineer is kept current on each project.

Ask us anything else

If your security questionnaire has a question this page does not answer, send it over. We answer questionnaires as part of procurement at no charge.

Send us your security questionnaire

Goes straight to our team on WhatsApp and email. We reply within one business day.

Desktop Mode