Before you let an outside team into your repositories and cloud accounts, you need to know exactly what they will and will not do with that access. This page answers that in plain language — including what we do not have.
Peer review before merge, no secrets committed to repositories, dependency and vulnerability scanning in the pipeline, and separate credentials for development, staging and production.
CI/CD runs with scoped, rotatable credentials. Infrastructure is defined as code so every change is reviewable, reversible and auditable rather than clicked into a console.
Our QA practice covers security testing alongside functional and performance testing, so problems are found before your users — or someone else — find them.
Our engineers use AI coding assistants daily — we are open about this because it affects your code, and you should be able to ask about it. Our AI-powered SDLC page explains how we work. The rules we hold ourselves to:
We are not ISO/IEC 27001 certified. We would rather tell you that here than have it surface in a procurement questionnaire. What we have instead is the set of practices on this page, applied consistently, and a willingness to be audited against yours.
If your process requires a certified supplier, tell us early — we will say honestly whether we can meet the requirement rather than waste your time.
We complete client security questionnaires and vendor-onboarding assessments as part of every enterprise engagement, and we are happy to walk your security team through any item on this page.
Send us the form your procurement team uses, or ask for our standard data processing agreement. We will come back to you within one business day.
Talk to us