Start a build

What we build

How we run it

Why us

Start a build

Typical first reply · under 4 hours

How we run it

How we handle
your data.

This page is the honest version rather than the reassuring one. If you need a formal security review before signing, ask — we would rather answer specifics than point at a badge.

We are a development company, not a compliance vendor, and we are not going to imply certifications we do not hold. What follows is what we actually do.

Access

  • Least privilege by default: engineers get access to what they are working on, and it is removed when they are not.
  • Multi-factor authentication on every account that supports it, including yours.
  • Credentials in a managed secret store — never in the repository, never in a spreadsheet, never in a chat message.
  • Access to production is separate from access to the codebase, and it is logged.

Your data

We work with production data only when there is no realistic alternative, and we use anonymised or synthetic data for development and testing wherever we can. When we do need production access, it is scoped, time-limited and logged.

The cloud account is in your name, so your customer data sits in infrastructure you control. If our relationship ends, nothing has to be extracted from us.

Backups

Automated, encrypted, and — the part that matters — restored on a schedule to prove they work. A backup that has never been restored is a hope. Retention and recovery targets are set per project and written into the retainer rather than assumed.

Reporting a vulnerability

If you have found a security issue in something we built or run, email us and we will acknowledge it within two business days. We will not threaten you, and we will credit you if you would like to be credited.

Compliance

HIPAA, PCI and SOC 2 scopes change the architecture, not just the paperwork, and they need to be on the table during discovery rather than discovered late. Tell us early and we will design for it — or tell you plainly if the scope is beyond what we should be taking on.

Questions people actually ask

Are you SOC 2 certified?

No. We will not imply a certification we do not hold. If your procurement process requires one from your vendors, tell us early — that is a legitimate constraint and it is better established in week one than in month four.

Who has access to our production data?

Only engineers actively working on your system, only when there is no workable alternative to production data, and access is logged. Development and testing use anonymised or synthetic data wherever that is possible.

What happens to our data if we stop working with you?

Nothing has to happen, because it is already in your cloud account. We remove our access, hand over the runbook and any credentials still held on your behalf, and that is the whole process.

Tell us what you are trying to ship.

A real technical opinion back within two business days — not a sales call.

Start a build