Skip to content

Security and data protection

Most security pages are a list of comforting words. This one is short, and every line on it is something you can check or hold us to.

It also has a list of things we do not have, near the bottom. That list is the more useful half of the page.

What we actually do

Version control from the first commit

Every project is in Git from day one, in a repository you own. Nothing reaches production without passing through it, so there is a history of what changed and when, and a way back if a change is wrong.

Staging before production

Changes go to a staging environment first and keep a restore point. A routine update cannot take your site down on a Friday afternoon, because the update is not applied blind to the live site.

HTTPS everywhere

Every site we ship is served over TLS, with certificates renewed automatically rather than by someone remembering. This site is no exception, which you can check in your address bar right now.

An NDA whenever you want one

Send your standard NDA and we sign it within 24 hours. You do not need to justify asking, and it can be in place before you describe the project in any detail.

The accounts are yours

The repository, the domain and the hosting account are in your name from day one. That is a security property as much as a commercial one: access does not have to be transferred at the end, because it was never ours to transfer.

Backups that have been restored

On the maintenance plan: off-site backups, and a restore that has actually been tested. A backup nobody has restored is a hypothesis rather than a backup. Plus uptime monitoring and security patching.

What we do not have

Our own cloud platform says the same kind of thing about itself: the data centres it runs on hold ISO 27001, CloudNX does not, and the case study says so rather than letting the data centre badge stand in for its own. The same honesty applies here.

  • We do not hold ISO 27001. We do not hold SOC 2. If a procurement process requires either, we are not the right supplier and we would rather you knew now.
  • We are not a 24/7 on-call operation as standard. What is covered outside our working day depends on your plan, so ask before you assume it.
  • We do not run a formal penetration testing practice. Where a build genuinely needs one, the right answer is a specialist firm, and we will say so.

Data protection by market

Where a build handles personal data, it is scoped against the regime that applies to your market rather than ours.

United Arab Emirates
the UAE Personal Data Protection Law (Federal Decree-Law 45 of 2021)
United Kingdom
the UK GDPR and the Data Protection Act 2018
Canada
PIPEDA, and provincial privacy law where it applies
United States
state privacy law, principally the CCPA and CPRA in California
India
the Digital Personal Data Protection Act 2023

If your procurement process needs something specific that is not on this page, ask rather than assuming either way. See also how a project runs and the privacy policy.

Security

Ask before you assume, in either direction.

If there is a control your procurement process needs, tell us on the first call. A straight no is more useful to you than a maybe.