Secure software development and code ownership
You are trusting us with your idea, your data and often your customers. This page explains how we protect them, and how you keep ownership of everything we build at every step.
- e3f1a9cfeat: invoice webhook and retries2h
- b72c04dtest: role checks on billing routes5h
- 9a01f6efeat: team roles and invitations1d
- c58d2b1chore: CI pipeline and staging deploy1d
- 4de7c30feat: subscription checkout2d
Agreements before you share anything
- 01 A mutual NDA in your panel, accepted before you upload confidential material
- 02 A master services agreement covering confidentiality, ownership, warranties and liability
- 03 Stage scopes that state exactly what each payment buys
- 04 Every acceptance recorded with name, date and the version accepted
Code ownership that transfers stage by stage
- 01 We commit to a repository you own from the first day of work
- 02 Intellectual property for the work in each stage transfers to you when that stage is paid
- 03 Infrastructure, domains, app store and cloud accounts are created in your name
- 04 At handover you get documentation, credentials in your vault and a written access list
- 05 If you stop after any stage, the code and documents from paid stages are already yours
Access by role and least privilege
- 01 Our team gets only the access the current work needs, removed when the work ends
- 02 You decide who on your side sees what in the panel: approvers, reviewers, finance
- 03 Two factor authentication on every account we use for your project
- 04 Secrets kept in a secrets manager, never in code or chat messages
- 05 Production data used only when the task requires it, and never copied to personal devices
Secure software development practices in every project
- 01 Code review on every change before it merges
- 02 Automated tests and dependency scanning in the deployment pipeline
- 03 Protection against common web risks: injection, broken access control, cross-site scripting, request forgery
- 04 Encryption in transit for every connection and at rest for sensitive data
- 05 Rate limits and bot protection on public forms
- 06 Logs that record security events without storing secrets or full payment data
- 07 Backups with restore tests, not just backups
Data in AI features
When we build AI features, your data is processed only for that feature. We choose provider settings that exclude your data from model training, and open models in your own infrastructure when data must stay there. Usage and cost caps are part of the code.
Report a security issue
If you find a vulnerability in anything we run, write to [email protected] with the details. We confirm receipt and keep you informed until it is fixed.
Security questions
Yes. Send your policies and questionnaires through the panel. We follow your access, device and data rules, and answer vendor questionnaires in writing.
In your repository, under your organization. We don't keep separate copies after the work ends.
Yes. Many projects run on staging only, with your team or a maintenance plan handling production releases.
Start with a confidential estimate
The estimate form needs no email. Accept the NDA in your panel before you share anything sensitive.