Skip to content
Security

For whoever fills the questionnaire

Current status, honestly stated, including what we do not hold. If a control is in progress we say in progress rather than compliant.

Status

Where each item actually stands

Nothing on this table is aspirational. In progress means work has started and a date exists.

ItemStatusDetail
SOC 2 Type IIPreparationControls roadmap in place. No audit date committed yet.
Mutual NDAAvailableStandard template, signed before any client system is discussed.
Data processing agreementAvailableOur standard DPA, or we sign yours after legal review.
Penetration testingAnnualLatest report summary shared on request.
Cyber insuranceActiveCertificate provided during procurement.
ISO 27001Not heldNot currently pursued. We will say so rather than imply otherwise.
Practice

How we work with your systems

Access

Least privilege by default. Client system access is time bound, individually named and revoked at hand over, not at invoice.

Credentials

No shared accounts. Secrets live in a managed store, never in a repository, a ticket or a chat message.

Devices

Full disk encryption, screen lock and managed updates on every device that touches client work.

Code

Branch protection, mandatory review, dependency scanning on every pull request and a release blocked by known high severity findings.

Data

We prefer not to hold client data at all. Where we must, it is minimized, encrypted at rest and deleted on a schedule agreed in the contract.

AI

Zero retention endpoints only, or inference inside your own tenancy. Client data is never used to train a third party model.

Residency

If your data cannot leave a jurisdiction or a network boundary, that is a design input, not an objection to work around. We have delivered inside boundaries that ruled out every hosted product on the market.

VPC deploymentOn premise inferenceRegion pinned storageNo cross border replication
Sub-processors

Third parties that may touch an engagement

This list is maintained here. Clients on a DPA are notified in writing before it changes.

ProviderPurposeRegion
Amazon Web ServicesCompute and storageClient selected
CloudflareEdge delivery and object storageGlobal, jurisdiction configurable
VercelApplication hostingUnited States
SupabaseManaged Postgres and authClient selected
SentryError monitoringUnited States
PostHogProduct analyticsUnited States
Incidents

What happens when something goes wrong

  1. 01

    Detect

    Alerting on error rate, auth anomalies and dependency advisories

  2. 02

    Notify

    Named client contact informed within 24 hours of confirmation

  3. 03

    Contain

    Credential rotation and access revocation before root cause analysis

  4. 04

    Report

    Written post incident review within 5 working days, shared in full

Development

Controls in the pipeline, not in a policy document

Each of these fails a build rather than raising a warning that somebody may read.

  • Dependency audit on every pull request
  • Secret scanning before commit and in CI
  • Mandatory review, no self merge
  • Infrastructure defined in code and reviewed
  • Signed releases with an immutable artifact
  • Production access logged and time bound
Documents

Available on request, usually same day

Data processing agreement

Standard DPA, or we review yours

Penetration test summary

Most recent third party letter

Insurance certificate

Cyber and professional indemnity

Security questionnaire

Completed CAIQ Lite or your own format

Send the questionnaire before the first call

It saves a round trip. We return completed vendor questionnaires within two working days, and we flag anything we cannot answer honestly rather than leaving it blank.