For whoever fills the questionnaire
Current status, honestly stated, including what we do not hold. If a control is in progress we say in progress rather than compliant.
Where each item actually stands
Nothing on this table is aspirational. In progress means work has started and a date exists.
| Item | Status | Detail |
|---|---|---|
| SOC 2 Type II | Preparation | Controls roadmap in place. No audit date committed yet. |
| Mutual NDA | Available | Standard template, signed before any client system is discussed. |
| Data processing agreement | Available | Our standard DPA, or we sign yours after legal review. |
| Penetration testing | Annual | Latest report summary shared on request. |
| Cyber insurance | Active | Certificate provided during procurement. |
| ISO 27001 | Not held | Not currently pursued. We will say so rather than imply otherwise. |
How we work with your systems
Access
Least privilege by default. Client system access is time bound, individually named and revoked at hand over, not at invoice.
Credentials
No shared accounts. Secrets live in a managed store, never in a repository, a ticket or a chat message.
Devices
Full disk encryption, screen lock and managed updates on every device that touches client work.
Code
Branch protection, mandatory review, dependency scanning on every pull request and a release blocked by known high severity findings.
Data
We prefer not to hold client data at all. Where we must, it is minimized, encrypted at rest and deleted on a schedule agreed in the contract.
AI
Zero retention endpoints only, or inference inside your own tenancy. Client data is never used to train a third party model.
Residency
If your data cannot leave a jurisdiction or a network boundary, that is a design input, not an objection to work around. We have delivered inside boundaries that ruled out every hosted product on the market.
Third parties that may touch an engagement
This list is maintained here. Clients on a DPA are notified in writing before it changes.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Compute and storage | Client selected |
| Cloudflare | Edge delivery and object storage | Global, jurisdiction configurable |
| Vercel | Application hosting | United States |
| Supabase | Managed Postgres and auth | Client selected |
| Sentry | Error monitoring | United States |
| PostHog | Product analytics | United States |
What happens when something goes wrong
- 01
Detect
Alerting on error rate, auth anomalies and dependency advisories
- 02
Notify
Named client contact informed within 24 hours of confirmation
- 03
Contain
Credential rotation and access revocation before root cause analysis
- 04
Report
Written post incident review within 5 working days, shared in full
Controls in the pipeline, not in a policy document
Each of these fails a build rather than raising a warning that somebody may read.
- Dependency audit on every pull request
- Secret scanning before commit and in CI
- Mandatory review, no self merge
- Infrastructure defined in code and reviewed
- Signed releases with an immutable artifact
- Production access logged and time bound
Available on request, usually same day
Data processing agreement
Standard DPA, or we review yours
Penetration test summary
Most recent third party letter
Insurance certificate
Cyber and professional indemnity
Security questionnaire
Completed CAIQ Lite or your own format
Send the questionnaire before the first call
It saves a round trip. We return completed vendor questionnaires within two working days, and we flag anything we cannot answer honestly rather than leaving it blank.