Skip to content
Security & Compliance

Enterprise security,by default.

Security isn't an add-on—it's built into everything we do. From how we access your systems to how we build AI applications, we follow the same controls used in regulated production systems.

Compliance Framework

Our compliance status and certification roadmap. We're transparent about where we are and where we're headed.

Security Review Support

Available

We work within client security review processes, vendor questionnaires, restricted access models, and code scanning requirements.

Healthcare Systems

Experienced

We have built and operated healthcare production systems and can work under client-required agreements and controls.

AWS & Azure Well-Architected

Aligned

Our cloud architectures follow AWS Well-Architected and Azure Well-Architected Framework best practices for security, reliability, and cost optimization.

Formal Certifications

Client-Specific

Formal certification and audit claims should be reviewed before publication and handled per engagement requirements.

Security Practices

Detailed overview of how we protect your data and systems.

Data Protection

Encryption at Rest

Production data stores are designed to use provider-managed encryption and client-approved key management patterns.

Encryption in Transit

Client-facing systems are designed to use TLS for network traffic and avoid unencrypted production connections.

Data Isolation

Client data and environments are scoped per engagement with no intentional data sharing between client workspaces.

Data Retention

Retention, deletion, and archival requirements are defined during scoping and aligned to client policy.

Access Control

Least Privilege

Access is scoped to the systems and permissions required for the engagement.

Multi-Factor Authentication

MFA and stronger access controls are used where supported by client and project systems.

Single Sign-On

SSO and automated access workflows are supported when provided by the client environment.

Audit Logging

Logging and retention expectations are documented for production systems and sensitive access paths.

Infrastructure Security

Cloud Security

AWS, Azure, or client-approved cloud infrastructure can be designed with network isolation, security groups, and edge protection.

Vulnerability Management

Dependency scanning, code scanning, and patch expectations are set to match the client's deployment and risk model.

DDoS Protection

Edge and DDoS protections are selected based on the hosting provider, exposure, and production requirements.

Network Segmentation

Production, staging, and development environments fully isolated.

AI-Specific Security

Prompt Injection Defense

Input validation, output filtering, and guardrails on all LLM applications.

PII Detection

PII detection, redaction, and routing controls are designed when workflows handle sensitive or regulated data.

Model Access Control

API keys rotated regularly. Rate limiting and usage monitoring on all model access.

Output Monitoring

Real-time monitoring for hallucinations, harmful content, and policy violations.

Operational Security

Security isn't just technical—it's how we operate as a company. These practices apply to every team member.

Background Checks

Background-check requirements can be handled during enterprise onboarding when required by the client.

Security Training

Security expectations, client policies, and project-specific handling rules are reviewed during kickoff.

Incident Response

Incident notification, escalation, and response expectations are documented before production access or launch.

Business Continuity

Continuity and recovery requirements are designed around the production criticality of the system.

Vendor Management

Security review required for all third-party tools and services.

Code Review

Code review and automated scanning expectations are aligned to the client's repository and release process.

Report a Security Issue

If you discover a security vulnerability or have concerns about our security practices, please contact us immediately. We take all reports seriously and will respond within 24 hours.

Security Documentation

Need our security questionnaire responses or other compliance documentation?

Frequently Asked Questions

Common questions from enterprise security and procurement teams.

Can you work under healthcare security requirements?

Yes. We have healthcare platform experience and can review client-required agreements, BAAs, access controls, and data-handling procedures during scoping.

Where is client data stored?

Client data is stored in AWS or Azure regions specified by the client (e.g., us-east-1, eu-west-1, or equivalent Azure regions). We do not store data in regions without explicit approval.

Do you have cyber insurance?

Insurance requirements can be reviewed during procurement and contracting.

Can you work within our security requirements?

Absolutely. We're experienced working within enterprise security frameworks, including VPN requirements, code scanning tools, and restricted network access.

How do you handle client source code?

Client code access is scoped through client-approved systems such as GitHub, GitLab, VPN, or cloud workspaces, with retention and device-handling expectations defined during onboarding.

What happens to our data after the engagement?

Data return, deletion, access removal, and written confirmation requirements are defined in the engagement terms.

Questions about our security?

We're happy to discuss our security practices, complete your security questionnaire, or connect you with our security team.