Security and trust
Your code, your infrastructure, your accounts — from day one.
How we handle your code, data and IP, stated specifically enough that you can check it. We hold no formal compliance certifications and we will not imply otherwise.
Standing terms
Six commitments that do not change per engagement
You own everything
Code, infrastructure, repositories and accounts are yours from day one, not on final payment. No lock-in, no hostage code, no surprise license fees.
NDA-friendly by default
Happy to sign your NDA before we discuss anything sensitive. Your idea, data and roadmap stay confidential, and IP assignment terms are explicit in every engagement.
Nothing merges unreviewed
Every change is reviewed by a senior engineer before it ships. Dependencies and secrets are scanned in CI. Access is least-privilege, and dev, staging and production are separate environments with separate credentials.
Data stays where you want it
Encryption in transit and at rest, scoped access to production data, and the ability to keep data inside your own infrastructure and region.
A record of what changed and when
Monitoring, logging and alerting so issues surface fast, and so there is a clear record of what changed and when.
Clean, documented handover
Readable code, docs and a walkthrough so your team, or your next developer, can run and extend it without us.
In practice
The specific things we do
No badge. A list you can hold us to instead.
- Signed NDAs and clear IP-assignment terms in every engagement
- Per-environment credentials with least-privilege access
- Secrets kept out of source control and rotated on handover
- Dependency and vulnerability scanning in CI
- Code review required before anything merges to production
- Encrypted data in transit (TLS) and at rest
- Payment integrations follow provider security requirements, including webhook verification and reconciliation
- Access revoked and accounts transferred to you at project close
Questions, answered
Are you SOC 2 or HIPAA certified?
No, and we will not imply otherwise. We hold no formal compliance certifications. Instead of a badge, the list of practices on this page is what we actually do, and every item on it is specific enough for you to check. If a certificate is a hard procurement requirement, an enterprise firm is the safer choice and we will tell you that on the first call.
When do I actually own the code?
From day one, not on final payment. You hold the repository, the infrastructure and every account the product runs on throughout the engagement. At close we revoke our access and transfer anything still in our name.
Will you sign our NDA?
Yes, before we discuss anything sensitive. We also assign IP explicitly in the engagement terms rather than leaving it implied.
Can our data stay in our own infrastructure?
Yes. We can deploy into your cloud accounts and keep data within your chosen region. For AI work specifically, model and hosting choices are made against your privacy requirements rather than defaulted.