Skip to main content

Security

Security is an operating responsibility.

We approach security through architecture, engineering, access control, monitoring, resilience, clear ownership, and continuous improvement.

This page describes an approach, not a claim of ISO certification, SOC examination, statutory audit, or universal compliance. Verified certifications and assurance reports should be listed only after formal approval.

Our Approach

Controls should reflect the system, data, threat, and responsibility.

Security requirements vary by service, client, architecture, jurisdiction, data category, and contract. The applicable control set and shared-responsibility model are defined for each engagement.

Secure Engineering

Threat-aware architecture, code review, dependency management, testing, remediation, environment separation, and controlled releases.

Identity & Access

Least privilege, strong authentication, role design, privileged-access control, session safeguards, and periodic review as appropriate.

Infrastructure Security

Configuration management, network controls, encryption, secrets handling, logging, monitoring, backup, and recovery planning.

Visibility & Response

Relevant telemetry, alerting, triage, escalation, containment, recovery, evidence preservation, and lessons learned.

Third-Party Risk

Review of material vendors, subprocessors, libraries, integrations, data access, contractual obligations, and operational dependencies.

Governance

Documented responsibilities, risks, exceptions, policies, changes, evidence, continuity plans, and improvement priorities.

Responsible Disclosure

Report a potential vulnerability safely.

Good-faith reports help protect customers, users, and systems. Send a concise description to Use the contact form. Include the affected hostname or product, steps to reproduce, observed impact, date and time, and a safe way to contact you.

Do not include unnecessary personal data, customer data, credentials, or destructive proof. Encrypt sensitive details only after agreeing on an appropriate channel.

Research boundaries

  • Do not access, copy, alter, or delete data that is not yours.
  • Do not disrupt availability, send spam, or perform denial-of-service testing.
  • Do not use social engineering, physical intrusion, or employee targeting.
  • Stop testing and report promptly if sensitive data becomes accessible.
  • Allow reasonable time to investigate and remediate before disclosure.
  • Comply with applicable law and any system-specific instructions.

Security enquiries versus customer incidents

The public security mailbox is for responsible vulnerability reports and general security enquiries. Existing customers should report suspected incidents through the approved contractual support or incident channel so authentication, severity, response, evidence, and escalation can be handled correctly.

Assurance information

Security documentation, architecture information, control evidence, questionnaires, independent reports, and contractual commitments may be provided according to the engagement, confidentiality requirements, and availability. Public website language does not replace a signed agreement or formal assurance report.

Security Services

Need help assessing or strengthening your environment?

We can discuss application, cloud, identity, risk, vulnerability management, response readiness, and remediation priorities.