Skip to main content
Security

How We Approach
Security

We're a growing engineering team, not yet a formally certified enterprise vendor. Here's an honest account of what we do today, and how we handle security conversations with clients who need more.

Encrypted in Transit

Every page on this site, and every project environment we run, is served over HTTPS with modern TLS and HSTS enforced - no unencrypted connections.

Hardened by Default

We apply standard security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) and follow secure-by-default configuration practices on the infrastructure we build and manage.

Requirements Discussed Directly

Every client has different compliance and security needs. Rather than publish a generic checklist, we work through your specific requirements - data residency, access controls, audit needs - directly during scoping.

No SOC 2 or ISO 27001 Certification Yet

We want to be upfront about this: we are not currently SOC 2 or ISO 27001 certified. If your organization requires a formally certified vendor for a specific engagement, we may not be the right fit today - and we'd rather tell you that directly than overstate our compliance posture.

If your security requirements are more flexible - documented practices, contractual data-handling commitments, and a direct conversation about your specific risk profile - we're glad to work through that with you before any engagement begins.

Have a Security Question?

If you have a specific security or compliance question - or need to report a vulnerability - reach out through our contact page and we'll respond directly.

Contact Us