Trust
How we secure what we build.
The controls we operate, the cadence we test them on, and how to reach us if you find something we missed.
What we operate.
| Domain | What we operate | Evidence available | ISO 27001 Annex A |
|---|---|---|---|
| Access control | SSO with enforced MFA, least-privilege roles, quarterly access review, offboarding within one business day | Access control policy | A.5.15, A.5.16, A.5.18, A.8.2, A.8.5 |
| Encryption | TLS 1.3 in transit, AES-256 at rest, customer-managed keys where the platform supports it | Architecture note | A.8.24 |
| Secure development | Peer review on every merge, SAST and dependency scanning in CI, ASVS L2 checklist at release | SDLC policy, sample pipeline run | A.8.25, A.8.26, A.8.28, A.8.29, A.8.31 |
| Penetration testing | Independent test before each major release and annually thereafter | Executive summary under NDA | A.8.8, A.8.29 |
| Supply chain | Pinned dependencies, signed builds, SBOM per release, CVE triage within a stated window | SBOM, provenance attestation | A.5.19, A.5.20, A.5.21, A.8.30 |
| Incident response | Named on-call, severity ladder, customer notification commitment in writing | IR plan, notification SLA | A.5.24, A.5.25, A.5.26, A.6.8 |
| Business continuity | Documented RTO and RPO per system, restore tested rather than assumed | BCP, last restore test date | A.5.29, A.5.30, A.8.13, A.8.14 |
| People | Background checks where law allows, NDAs, annual security training with completion tracked | Training records summary | A.6.1, A.6.2, A.6.3, A.6.6 |
What happens to every change.
Peer reviewNo change reaches a main branch without another engineer approving it.
Automated scanningStatic analysis and dependency scanning run in CI on every pull request. A build with an unresolved high-severity finding does not merge.
Verification at releaseAn OWASP ASVS Level 2 checklist is completed per release, and the OWASP Top 10 and API Top 10 are regression-tested.
ProvenanceBuilds are signed, dependencies are pinned, and a CycloneDX SBOM is issued with every release.
Independent testingA penetration test before each major release and annually thereafter. Executive summaries are available under NDA.
Incident response.
A named engineer is on call. Incidents are triaged against a published severity ladder, and the notification commitment to affected customers is in writing in the contract rather than decided during the incident. Response times are published in full on How we work.
Report a vulnerability.
If you believe you have found a vulnerability in anything we run, email [email protected]. We will acknowledge within one business day and keep you updated until it is resolved. We will not pursue legal action against good-faith research that respects customer data and stops at proof of concept.