Security and data protection
Most security pages are a list of comforting words. This one is short, and every line on it is something you can check or hold us to.
It also has a list of things we do not have, near the bottom. That list is the more useful half of the page.
What we actually do
Version control from the first commit
Every project is in Git from day one, in a repository you own. Nothing reaches production without passing through it, so there is a history of what changed and when, and a way back if a change is wrong.
Staging before production
Changes go to a staging environment first and keep a restore point. A routine update cannot take your site down on a Friday afternoon, because the update is not applied blind to the live site.
HTTPS everywhere
Every site we ship is served over TLS, with certificates renewed automatically rather than by someone remembering. This site is no exception, which you can check in your address bar right now.
An NDA whenever you want one
Send your standard NDA and we sign it within 24 hours. You do not need to justify asking, and it can be in place before you describe the project in any detail.
The accounts are yours
The repository, the domain and the hosting account are in your name from day one. That is a security property as much as a commercial one: access does not have to be transferred at the end, because it was never ours to transfer.
Backups that have been restored
On the maintenance plan: off-site backups, and a restore that has actually been tested. A backup nobody has restored is a hypothesis rather than a backup. Plus uptime monitoring and security patching.
What we do not have
Our own cloud platform says the same kind of thing about itself: the data centres it runs on hold ISO 27001, CloudNX does not, and the case study says so rather than letting the data centre badge stand in for its own. The same honesty applies here.
- We do not hold ISO 27001. We do not hold SOC 2. If a procurement process requires either, we are not the right supplier and we would rather you knew now.
- We are not a 24/7 on-call operation as standard. What is covered outside our working day depends on your plan, so ask before you assume it.
- We do not run a formal penetration testing practice. Where a build genuinely needs one, the right answer is a specialist firm, and we will say so.
Data protection by market
Where a build handles personal data, it is scoped against the regime that applies to your market rather than ours.
If your procurement process needs something specific that is not on this page, ask rather than assuming either way. See also how a project runs and the privacy policy.