Skip to main content
Security and trust

No badge. Here is the actual list instead.

We are not formally certified, so rather than a compliance logo, this page states exactly how your code, data and IP are handled. Every item below is specific enough to hold us to.

Principles

Six commitments that do not vary by project

01

You own everything

Code, infrastructure, repositories and accounts are yours from day one, not on final payment. No lock-in, no hostage code, no surprise license fees.
02

NDA-friendly by default

Happy to sign your NDA before we discuss anything sensitive. Your idea, data and roadmap stay confidential, and IP assignment terms are explicit in every engagement.
03

Secure development lifecycle

Code review on every change, dependency and secret scanning, least-privilege access, and environment separation across dev, staging and production.
04

Sensible data handling

Encryption in transit and at rest, scoped access to production data, and the ability to keep data inside your own infrastructure and region.
05

Auditable and observable

Monitoring, logging and alerting so issues surface fast, and so there is a clear record of what changed and when.
06

Clean, documented handover

Readable code, docs and a walkthrough so your team, or your next developer, can run and extend it without us.

Practices

What that means in the repository

Concrete, checkable, and applied on a 21-day build exactly as on a twelve-month retainer.
Signed NDAs and clear IP-assignment terms in every engagement
Per-environment credentials with least-privilege access
Secrets kept out of source control and rotated on handover
Dependency and vulnerability scanning in CI
Code review required before anything merges to production
Encrypted data in transit (TLS) and at rest
Payment integrations follow provider security requirements, including webhook verification and reconciliation
Access revoked and accounts transferred to you at project close

Where the line is

What we do not have

We hold no SOC 2 or HIPAA certification, we run no regulated-industry audit programme, and we do not staff a 24/7 security desk. Saying so is not a disclaimer. It is the reason the list above is worth reading.

If certified compliance is a requirement, hire a firm that holds the certificate. If what you need is an engineering team that reviews every change, scans dependencies, rotates secrets and hands you everything at the end, that is what this page describes. More on the boundary in who we are not for.

FAQ

Security questions we get asked

Are you SOC 2 or HIPAA certified?+
No, and we will not imply otherwise. We hold no formal compliance certifications. Instead of a badge, the list of practices on this page is what we actually do, and every item on it is specific enough for you to check. If a certificate is a hard procurement requirement, an enterprise firm is the safer choice and we will tell you that on the first call.
When do I actually own the code?+
From day one, not on final payment. You hold the repository, the infrastructure and every account the product runs on throughout the engagement. At close we revoke our access and transfer anything still in our name.
Will you sign our NDA?+
Yes, before we discuss anything sensitive. We also assign IP explicitly in the engagement terms rather than leaving it implied.
Can our data stay in our own infrastructure?+
Yes. We can deploy into your cloud accounts and keep data within your chosen region. For AI work specifically, model and hosting choices are made against your privacy requirements rather than defaulted.

Have a security or compliance question?

Ask it directly. If the answer is that we are not the right fit for your compliance requirements, you will get that answer rather than a hedge.
Talk to us