Security
Security is an operating responsibility.
We approach security through architecture, engineering, access control, monitoring, resilience, clear ownership, and continuous improvement.
This page describes an approach, not a claim of ISO certification, SOC examination, statutory audit, or universal compliance. Verified certifications and assurance reports should be listed only after formal approval.
Our Approach
Controls should reflect the system, data, threat, and responsibility.
Security requirements vary by service, client, architecture, jurisdiction, data category, and contract. The applicable control set and shared-responsibility model are defined for each engagement.
Secure Engineering
Threat-aware architecture, code review, dependency management, testing, remediation, environment separation, and controlled releases.
Identity & Access
Least privilege, strong authentication, role design, privileged-access control, session safeguards, and periodic review as appropriate.
Infrastructure Security
Configuration management, network controls, encryption, secrets handling, logging, monitoring, backup, and recovery planning.
Visibility & Response
Relevant telemetry, alerting, triage, escalation, containment, recovery, evidence preservation, and lessons learned.
Third-Party Risk
Review of material vendors, subprocessors, libraries, integrations, data access, contractual obligations, and operational dependencies.
Governance
Documented responsibilities, risks, exceptions, policies, changes, evidence, continuity plans, and improvement priorities.
Responsible Disclosure
Report a potential vulnerability safely.
Good-faith reports help protect customers, users, and systems. Send a concise description to Use the contact form. Include the affected hostname or product, steps to reproduce, observed impact, date and time, and a safe way to contact you.
Do not include unnecessary personal data, customer data, credentials, or destructive proof. Encrypt sensitive details only after agreeing on an appropriate channel.
Research boundaries
- Do not access, copy, alter, or delete data that is not yours.
- Do not disrupt availability, send spam, or perform denial-of-service testing.
- Do not use social engineering, physical intrusion, or employee targeting.
- Stop testing and report promptly if sensitive data becomes accessible.
- Allow reasonable time to investigate and remediate before disclosure.
- Comply with applicable law and any system-specific instructions.
Security enquiries versus customer incidents
The public security mailbox is for responsible vulnerability reports and general security enquiries. Existing customers should report suspected incidents through the approved contractual support or incident channel so authentication, severity, response, evidence, and escalation can be handled correctly.
Assurance information
Security documentation, architecture information, control evidence, questionnaires, independent reports, and contractual commitments may be provided according to the engagement, confidentiality requirements, and availability. Public website language does not replace a signed agreement or formal assurance report.
Security Services
Need help assessing or strengthening your environment?
We can discuss application, cloud, identity, risk, vulnerability management, response readiness, and remediation priorities.