Trust Center
Security overview
This is a public, non-exhaustive summary of how we approach information security for systems we build and operate. It intentionally omits detail that would assist attackers. Additional evidence is available to authorized parties via request-access.
Governance
- Named security owner among the founders
- Risk assessment for material systems
- Vendor and subprocessor review before onboarding, with the list published
- Policy review at least annually; each policy carries its version and dates
Access control
- Least privilege and role-based access
- Multifactor authentication for privileged access
- Access limited to the founders and named contractors per engagement, revoked when the engagement closes
Secure development
- Peer review for material codebases
- Dependency vulnerabilities reviewed on every website release; automated dependency and secret scanning enabled on customer repositories when in scope
- Environment separation and no production secrets in source control
- Vulnerability remediation tracked by severity
Cloud and data protection
- Encryption in transit (TLS) for the public website and client connections we control
- Encryption at rest for systems where we manage storage configuration
- Backups for in-scope customer systems as agreed in the statement of work; this website is rebuilt from version-controlled source on every deploy
- Logging of security-relevant events for systems we operate
Vulnerability management and incident response
We monitor dependencies, patch on a risk basis, and welcome reports under Responsible disclosure. We maintain an incident process covering detection, containment, eradication, recovery, and stakeholder communication.
What we do not claim
We do not claim to be unhackable, certified under any framework, or an official partner of cloud or payment vendors, unless current written evidence is published with our approval.