Trust & security

Built to pass your scrutiny.

Corporate engagements come with procurement processes, security reviews and compliance teams. Rightly so. This page explains exactly how we handle that, so you do not have to assume anything.

Confidentiality

NDA as standard, not as a favour

We sign a non-disclosure agreement without discussion, including for a first exploratory conversation. Your plans, figures and code are treated with the same care as our own. Client work appears on our website only with explicit permission.

Ownership

Everything remains yours

Source code, designs, documentation and data are and remain the property of the client. We build with transferability as the starting point: clear documentation, mainstream technology and no artificial dependency on us.

Security

Secure from the first line

Encrypted traffic, least-privilege access, separated environments, up-to-date dependencies and backups are our baseline, not an option. Hosting takes place within the European Union. On request, delivered systems are tested by an external penetration testing party.

Your organisation

We plug into your process

Vendor assessments, security questionnaires, data processing agreements and conversations with your IT and compliance teams are part of our work. We provide the documentation your procurement process requires and work within your environments and guidelines where needed.

Full transparency: we do not hold an ISO certification. We do work according to those principles, document our way of working and provide the material your auditor or security team needs with every engagement. If your organisation requires more, we discuss it in the first conversation, not halfway through the project.

Due diligence

Does your procurement or security team have questions?

Ask them directly. We respond within one business day, questionnaires included.