Security & Trust
Security and trust at every stage of the project.
Trusting a new vendor with your data and code is a serious decision. That’s why we make the real practices we apply on every project public - before you even have to ask.
We don’t yet hold formal certifications like ISO 27001, but we’ve applied these practices since our first project and are open to assessments and specific adjustments required by larger clients.
Code versioning and history
All code is version-controlled in Git, with an auditable history, protected branches and review before any change reaches production.
Form data handling
Data submitted through forms travels over an encrypted connection (HTTPS/TLS) and access is restricted to the team responsible for handling it.
Non-disclosure agreement (NDA)
We provide an NDA before discovery meetings or any sharing of sensitive information about your business.
Data protection and privacy by design
We follow principles of data minimization, limited retention and a direct channel for data subject requests, aligned with data protection regulations.
Access control
Role-based permissions (least privilege) and separation between development, staging and production environments.
Continuity and backups
Backup routines and recovery plans to reduce the risk of data or code loss throughout the project.
Do you have a specific security requirement?
Larger companies often have their own compliance requirements. Tell us what your security team requires and we’ll assess it together.
