Skip to content
Security & Compliance

Security is a requirement, not a feature

What we commit to before signing — the answers your procurement and IT teams will ask for.

Roles and authorisation

  • Role-based access; users see only the data they are entitled to
  • Multi-factor authentication for administrative access
  • Permission changes are logged
  • Approval flows for privileged operations

Data security

  • TLS in transit, encryption at rest
  • Credentials and API keys never live in the repository
  • Databases reachable only from an isolated internal network
  • Dependency vulnerability scanning

Audit trail

  • Who changed which record, when, from which value to which
  • Price, approval, limit and permission actions recorded separately
  • Records cannot be deleted through the application
  • Exportable audit report

Backup and continuity

  • Daily automated database backups with a retention policy
  • Restore testing — an untested backup is not a backup
  • Health checks and automatic restart
  • RTO and RPO targets defined in the contract

Data protection compliance

  • Controller and processor roles defined in the contract
  • Disclosure text and consent management
  • Retention per data type; deletion or anonymisation at the end
  • Breach notification procedure with named owners

Dependency and exit

  • Card data is never stored; payment is handed to a compliant provider
  • Export format and timeline written upfront
  • Handover and deletion procedure at contract end
  • Source code transfer terms defined explicitly

We run what we build

Our own products run on the same infrastructure we deliver to clients: isolated container networks, automatic TLS, daily backups, health checks and monitoring. These are not slides — they are how our systems have been operating every day.