Skip to content
Trust

How we secure what we build.

The controls we operate, the cadence we test them on, and how to reach us if you find something we missed.

What we operate.

TechLand Engineering control register: what we operate in each domain, the evidence available on request, and the ISO/IEC 27001 Annex A controls each domain maps to.
DomainWhat we operateEvidence availableISO 27001 Annex A
Access controlSSO with enforced MFA, least-privilege roles, quarterly access review, offboarding within one business dayAccess control policyA.5.15, A.5.16, A.5.18, A.8.2, A.8.5
EncryptionTLS 1.3 in transit, AES-256 at rest, customer-managed keys where the platform supports itArchitecture noteA.8.24
Secure developmentPeer review on every merge, SAST and dependency scanning in CI, ASVS L2 checklist at releaseSDLC policy, sample pipeline runA.8.25, A.8.26, A.8.28, A.8.29, A.8.31
Penetration testingIndependent test before each major release and annually thereafterExecutive summary under NDAA.8.8, A.8.29
Supply chainPinned dependencies, signed builds, SBOM per release, CVE triage within a stated windowSBOM, provenance attestationA.5.19, A.5.20, A.5.21, A.8.30
Incident responseNamed on-call, severity ladder, customer notification commitment in writingIR plan, notification SLAA.5.24, A.5.25, A.5.26, A.6.8
Business continuityDocumented RTO and RPO per system, restore tested rather than assumedBCP, last restore test dateA.5.29, A.5.30, A.8.13, A.8.14
PeopleBackground checks where law allows, NDAs, annual security training with completion trackedTraining records summaryA.6.1, A.6.2, A.6.3, A.6.6

What happens to every change.

Peer reviewNo change reaches a main branch without another engineer approving it.
Automated scanningStatic analysis and dependency scanning run in CI on every pull request. A build with an unresolved high-severity finding does not merge.
Verification at releaseAn OWASP ASVS Level 2 checklist is completed per release, and the OWASP Top 10 and API Top 10 are regression-tested.
ProvenanceBuilds are signed, dependencies are pinned, and a CycloneDX SBOM is issued with every release.
Independent testingA penetration test before each major release and annually thereafter. Executive summaries are available under NDA.

Incident response.

A named engineer is on call. Incidents are triaged against a published severity ladder, and the notification commitment to affected customers is in writing in the contract rather than decided during the incident. Response times are published in full on How we work.

Report a vulnerability.

If you believe you have found a vulnerability in anything we run, email [email protected]. We will acknowledge within one business day and keep you updated until it is resolved. We will not pursue legal action against good-faith research that respects customer data and stops at proof of concept.