How we protect your code, data and systems

Before you let an outside team into your repositories and cloud accounts, you need to know exactly what they will and will not do with that access. This page answers that in plain language — including what we do not have.

Confidentiality
Mutual NDA before anything is shared
Intellectual property
Code and work product assign to you
Personal data
Thailand PDPA, GDPR as a processor
AI tools
Business accounts, no training on your code
ISO/IEC 27001
Not certified — see below
Contracts

Confidentiality and intellectual property

  • Mutual NDA first. We sign a mutual non-disclosure agreement before you share anything confidential — including at the proposal stage. We are happy to sign your paper rather than ours.
  • Every employee is bound. Everyone who joins Sequence Technologies signs a confidentiality undertaking as part of their employment contract, and it survives the end of their employment.
  • Your intellectual property stays yours. Source code, designs, documentation and other work product created for you assign to you. We claim no licence over your business logic or data.
  • Pre-existing and open-source components are declared. Where we reuse our own libraries or open-source packages, we tell you which ones and under which licence, so your legal team is never surprised.
Access

Who can reach your systems, and how

Accounts and authentication

  • Named individual accounts only — never shared logins
  • Multi-factor authentication on every account that supports it
  • Least privilege: people get the access their task needs, and no more
  • We prefer to work inside accounts you issue and can revoke at any moment
  • Access is removed the same working day someone leaves the project or the company

Devices and networks

  • Full-disk encryption and automatic screen lock on work machines
  • Operating system and browser kept on supported, patched versions
  • Credentials kept in a password manager, never in chat, email or code
  • Client VPN or bastion access used wherever you provide one
  • Where you require it, we can work only from our Bangkok office
Data

How we handle your data

  • We work in your environment where we can. Repositories, cloud accounts and databases stay under your ownership and control. We are users in your tenancy, not a copy of it in ours.
  • Production data does not come to us. Development and testing use masked or synthetic data. Where a real extract is genuinely unavoidable, it happens under written agreement, for a defined period.
  • Nothing is kept once it is no longer needed. At the end of an engagement we return or delete client data and hand back credentials, and confirm in writing when it is done.
  • Backups belong to you. We help you design and test backup and recovery for your systems; we do not hold shadow copies of your data for our own purposes.
Engineering

Secure development practices

In the codebase

Peer review before merge, no secrets committed to repositories, dependency and vulnerability scanning in the pipeline, and separate credentials for development, staging and production.

In the pipeline

CI/CD runs with scoped, rotatable credentials. Infrastructure is defined as code so every change is reviewable, reversible and auditable rather than clicked into a console.

Before release

Our QA practice covers security testing alongside functional and performance testing, so problems are found before your users — or someone else — find them.

AI tools

AI in our workflow, and what it means for your code

Our engineers use AI coding assistants daily — we are open about this because it affects your code, and you should be able to ask about it. Our AI-powered SDLC page explains how we work. The rules we hold ourselves to:

  • Business and enterprise accounts only, on plans where the provider does not train models on the content we send, so your code is never used to train a model.
  • A human is accountable for every line. AI-assisted code goes through the same review, testing and sign-off as anything else. "The model wrote it" is not an explanation we accept internally.
  • You can opt out. If your policy forbids AI assistants touching your codebase, we will run your project without them and say so in writing.
  • Secrets and personal data never go into a prompt.
Legal

Personal data, PDPA and GDPR

  • Thailand PDPA. We comply with the Personal Data Protection Act B.E. 2562 for the personal data we hold — visitors, candidates and client contacts. Our Privacy Policy sets out what we collect, why, and how to exercise your rights.
  • Processor for our clients. Where we handle personal data on your behalf we act as a data processor on your instructions, and we will sign a data processing agreement.
  • GDPR. For clients in Europe we can contract on GDPR processor terms, including standard contractual clauses for transfers to Thailand.
  • Breach notification. If personal data is exposed we tell you without undue delay so you can meet your own obligations — PDPA requires notification to the regulator within 72 hours.
  • Cookies. This website loads analytics only after you accept, and you can change your choice at any time from the link in the footer.
Certifications

What we are certified for — and what we are not

We are not ISO/IEC 27001 certified. We would rather tell you that here than have it surface in a procurement questionnaire. What we have instead is the set of practices on this page, applied consistently, and a willingness to be audited against yours.

If your process requires a certified supplier, tell us early — we will say honestly whether we can meet the requirement rather than waste your time.

We complete client security questionnaires and vendor-onboarding assessments as part of every enterprise engagement, and we are happy to walk your security team through any item on this page.

Need our security questionnaire or a DPA?

Send us the form your procurement team uses, or ask for our standard data processing agreement. We will come back to you within one business day.

Talk to us