Security & trust
How we handle access, data, AI permissions and ongoing care — written for security reviews, not marketing.
Procurement shortcut
DPA · NDA · SLAsQuestionnaires completed within 5 business days.
Request our security packControls, per engagement
Every engagement ships with an access list, a data map and a support/SLA annex.
Client systems are accessed through named accounts with minimal scopes, time-boxed where possible. No shared credentials. Secrets live in environment stores, never in repos or chat.
We sign NDAs before discovery and DPAs where personal data is processed. Data purposes, retention and sub-processors are documented per engagement.
Updates, WAF/CDN, backups, monitoring and restore drills are part of every launch checklist — WordPress, Shopify and custom stacks alike.
Agents run with scoped permissions, human approval for consequential actions, and audit logs. Prototypes run on sample data; production connects only after sign-off.
Azure and GCP work behind landing zones with guardrails, budgets and Terraform-managed infrastructure. Identity runs on Entra ID with conditional access, least-privilege roles and break-glass accounts — documented for audit.
Data & hosting
Repositories, hosting, domains and analytics live in your organisation with our team as collaborators — never the reverse. IP in deliverables transfers on final payment.
Backups are versioned and restore-tested; monitoring covers uptime, errors and Core Web Vitals. Care plans add response-time SLAs (24×7, every day of the week) with severity levels in writing.
Sub-processors are limited to the delivery stack you approve (e.g. Vercel, Neon, Resend/Zoho, Upstash) plus your own cloud tenancy (Azure/GCP), CRM and ads platforms. No data sale, no training on your data.
Have something in mind?
Send your template — we return it within 5 business days.