Security & Compliance
This page exists so your procurement and security teams can get answers without waiting on an email thread. If a line here is not detailed enough for your questionnaire, ask — we would rather answer now than at contract stage.
Data protection
- Where data lives. Client data stays in the client’s own environment and chosen region. We build and test against sanitised or synthetic data unless you explicitly provide otherwise.
- GDPR and local law. We sign your data-processing agreement, or provide ours. Processing terms follow the jurisdiction you nominate in the contract.
- Retention and deletion. Project material is removed from our systems on request at the end of an engagement, and a written confirmation is provided.
- Sub-processors. Any third party that would touch your data — hosting, email, analytics, AI tooling — is listed in the statement of work before it is used. None is introduced mid-project without notice.
Certifications and assurance
We share our current certification and independent-audit status in writing during procurement, so that what you rely on is a dated document rather than a web page. Penetration-test summaries for work we have delivered can be shared under NDA with the client’s consent.
How we work securely
- Access. Named accounts only, multi-factor authentication on the tools that hold client work, least-privilege by default, and access revoked on the day someone leaves a project.
- Devices. Client work is done on company-managed machines with full-disk encryption and automatic screen-lock.
- Code. Private repositories, review before merge, dependency scanning, and secrets kept out of source control — always in a vault or environment configuration.
- Environments. Production, staging and development are kept separate. Client production credentials are never copied into development.
- People. Engineers with access to client systems are identity-verified; enhanced background screening is arranged where your policy requires it.
Contracts and commercial
- NDA. We sign yours, or provide ours — whichever your legal team prefers.
- MSA / SOW. We work under our standard master agreement or under the client’s paper.
- IP ownership. Deliverables and their source code are assigned to you on final payment. Pre-existing tooling we bring is identified in the SOW and licensed to you for the deliverable.
- Insurance and escrow. Professional-indemnity cover and source-code escrow arrangements are provided on request and agreed per engagement.
Availability and support
- Coverage. Nine locations across Asia, the Middle East, Europe, the Americas and Australia give near-continuous coverage across business days.
- Response targets. Set per engagement and written into the SOW, with severity tiers you can hold us to.
- Escalation. Every engagement has a named delivery lead and a named escalation contact above them, both in the SOW.
- Continuity. No client depends on a single engineer: work is documented in the repository and at least one other engineer is kept current on each project.
Ask us anything else
If your security questionnaire has a question this page does not answer, send it over. We answer questionnaires as part of procurement at no charge.
