1. Principles
- Least privilege and separation of duties in access to systems and data.
- Encryption of data in transit; protection of data at rest according to its classification.
- Change review before release, with traceability of who approved what.
- Data minimization: we collect only what a purpose requires.
- Security considered from design, not added after delivery.
2. Operational practices
We maintain dependency review, logging appropriate to the risk, and internal procedures for handling incidents and notifying affected parties where required. [CONFIRM] Incident-response commitments, notification windows and any customer-facing SLA before stating them publicly.
We do not publish provider names, network topology, control configurations, tooling or credentials handling. Sharing that detail is done only under agreement with parties that have a legitimate need.
3. Certifications
No certification, attestation or audit result is claimed on this page. Any future certification will be published only once formally obtained and verifiable. [CONFIRM] Certification roadmap.
4. Reporting a vulnerability
If you believe you have found a vulnerability, report it privately to [PLACEHOLDER — security reporting mailbox] with enough detail to reproduce it. Please do not run tests that degrade service, access third-party data or exfiltrate information. [CONFIRM] Coordinated-disclosure policy, safe-harbour language and response times.
Questions about this document? Write to us through the contact form.
Contact