Security Practices

How we protect your product & data

This page explains how we protect client data, source code, and systems. Security is built into our process — not added as an afterthought.

What we protect

We treat everything you share with us as confidential.

Source Code

Your codebase is stored in private repositories with access limited to assigned team members only.

Credentials & Secrets

API keys, passwords, and secrets are never hardcoded. We use environment variables and secret managers.

Client Data

Any data you share with us is treated as confidential. We follow data minimization principles.

Intellectual Property

Your ideas and IP remain yours. Contracts use present-assignment ("hereby assign") language so rights vest in you as work is created — plus NDAs and optional source-code escrow.

How we protect

Security measures we implement on every project.

Secure Connections

  • HTTPS enforced on all deployments
  • TLS 1.3 for data in transit
  • HTTP security headers configured
  • HSTS enabled where applicable

Infrastructure Security

  • Secure cloud hosting (AWS, Vercel, etc.)
  • Encrypted data at rest
  • Automated backups
  • DDoS protection via CDN

Access Control

  • Role-based permissions
  • Two-factor authentication
  • Limited access to production
  • Audit logs for sensitive actions

Testing & Review

  • Code reviews before merge
  • Automated testing on all PRs
  • Dependency vulnerability scanning
  • Manual QA before release

Secure Development

  • Input validation (server-side)
  • Output encoding to prevent XSS
  • Parameterized queries for SQL
  • CSRF protection on forms

Monitoring

  • Error monitoring and alerts
  • Performance monitoring
  • Uptime monitoring
  • Security event logging

What we don't do

Clear boundaries we maintain for your protection.

We never: Store passwords in plain text
We never: Share your code with third parties
We never: Deploy without code review
We never: Access production data without need
We never: Use your project for marketing without permission
We never: Collect more data than necessary

We sign NDAs — your ideas stay yours

We're happy to sign a mutual NDA before any discussion. Download our standard template or send us yours — we're flexible.

A note on compliance

We follow security best practices but are not currently SOC2 or ISO certified. If your project requires specific compliance certifications, let us know during our initial discussion — we can recommend partners or adjust our approach accordingly.

Compliance roadmap: We are evaluating SOC 2 Type I readiness for 2027, with ongoing investments in audit logging, access controls, and incident response documentation.

Trust & security FAQ

The questions buyers ask us before they sign.

Who owns the intellectual property and source code?+

You do — completely. Our contracts use present-assignment ("hereby assign") language, so all IP and source code rights vest in you by operation of law as the work is created, not merely as a future promise. You get full ownership of the codebase, and we can add source-code escrow for mission-critical systems on request.

Do you sign NDAs and Data Processing Agreements (DPAs)?+

Yes. We sign a mutual NDA before any detailed discussion — ours or yours. For projects handling personal data, we can sign a GDPR-aligned Data Processing Agreement and follow data-minimization and least-privilege practices.

Are you SOC 2 or ISO 27001 certified?+

Not yet — we are a small, founder-led firm and we will not claim certifications we do not hold. We follow SOC 2 / ISO 27001-aligned practices (access control, audit logging, encryption, code review, incident response) and are building toward formal SOC 2 Type I readiness. If your procurement requires a specific certification today, tell us early and we will be straight with you about fit.

How do you protect data in regulated sectors (fintech, healthtech)?+

We engineer to the requirements your compliance partner sets — PCI-conscious payment flows for fintech, HIPAA/GDPR-conscious handling of health data — with encryption in transit and at rest, least-privilege access, and append-only audit logging. We have built a fintech dashboard and a healthcare scheduling app for clients, but we have not shipped a regulated or licensed fintech or health product, and we do not interpret regulation for you. We can provide a penetration-test summary on request for engagements that require it.

How do we verify your security before signing?+

Ask us for our security overview, IP-assignment clause, NDA/DPA templates, and references. We are happy to walk your team through our practices on a call — security should be verifiable, not just asserted.

Questions about security?

We're happy to discuss our practices in detail. Security is something we take seriously.

Contact us