How we protect your product & data
This page explains how we protect client data, source code, and systems. Security is built into our process — not added as an afterthought.
What we protect
We treat everything you share with us as confidential.
Source Code
Your codebase is stored in private repositories with access limited to assigned team members only.
Credentials & Secrets
API keys, passwords, and secrets are never hardcoded. We use environment variables and secret managers.
Client Data
Any data you share with us is treated as confidential. We follow data minimization principles.
Intellectual Property
Your ideas and IP remain yours. Contracts use present-assignment ("hereby assign") language so rights vest in you as work is created — plus NDAs and optional source-code escrow.
How we protect
Security measures we implement on every project.
Secure Connections
- HTTPS enforced on all deployments
- TLS 1.3 for data in transit
- HTTP security headers configured
- HSTS enabled where applicable
Infrastructure Security
- Secure cloud hosting (AWS, Vercel, etc.)
- Encrypted data at rest
- Automated backups
- DDoS protection via CDN
Access Control
- Role-based permissions
- Two-factor authentication
- Limited access to production
- Audit logs for sensitive actions
Testing & Review
- Code reviews before merge
- Automated testing on all PRs
- Dependency vulnerability scanning
- Manual QA before release
Secure Development
- Input validation (server-side)
- Output encoding to prevent XSS
- Parameterized queries for SQL
- CSRF protection on forms
Monitoring
- Error monitoring and alerts
- Performance monitoring
- Uptime monitoring
- Security event logging
What we don't do
Clear boundaries we maintain for your protection.
We sign NDAs — your ideas stay yours
We're happy to sign a mutual NDA before any discussion. Download our standard template or send us yours — we're flexible.
A note on compliance
We follow security best practices but are not currently SOC2 or ISO certified. If your project requires specific compliance certifications, let us know during our initial discussion — we can recommend partners or adjust our approach accordingly.
Compliance roadmap: We are evaluating SOC 2 Type I readiness for 2027, with ongoing investments in audit logging, access controls, and incident response documentation.
Trust & security FAQ
The questions buyers ask us before they sign.
Who owns the intellectual property and source code?+
You do — completely. Our contracts use present-assignment ("hereby assign") language, so all IP and source code rights vest in you by operation of law as the work is created, not merely as a future promise. You get full ownership of the codebase, and we can add source-code escrow for mission-critical systems on request.
Do you sign NDAs and Data Processing Agreements (DPAs)?+
Yes. We sign a mutual NDA before any detailed discussion — ours or yours. For projects handling personal data, we can sign a GDPR-aligned Data Processing Agreement and follow data-minimization and least-privilege practices.
Are you SOC 2 or ISO 27001 certified?+
Not yet — we are a small, founder-led firm and we will not claim certifications we do not hold. We follow SOC 2 / ISO 27001-aligned practices (access control, audit logging, encryption, code review, incident response) and are building toward formal SOC 2 Type I readiness. If your procurement requires a specific certification today, tell us early and we will be straight with you about fit.
How do you protect data in regulated sectors (fintech, healthtech)?+
We engineer to the requirements your compliance partner sets — PCI-conscious payment flows for fintech, HIPAA/GDPR-conscious handling of health data — with encryption in transit and at rest, least-privilege access, and append-only audit logging. We have built a fintech dashboard and a healthcare scheduling app for clients, but we have not shipped a regulated or licensed fintech or health product, and we do not interpret regulation for you. We can provide a penetration-test summary on request for engagements that require it.
How do we verify your security before signing?+
Ask us for our security overview, IP-assignment clause, NDA/DPA templates, and references. We are happy to walk your team through our practices on a call — security should be verifiable, not just asserted.
Questions about security?
We're happy to discuss our practices in detail. Security is something we take seriously.
Contact us