Information security controls
We use ISO 27001 requirements as the reference for building and periodically reviewing our security controls. We claim no certificate unless it is current, and we provide it on request.
Our commitment to protecting our clients' data and systems to the highest international standards.
We use ISO 27001 requirements as the reference for building and periodically reviewing our security controls. We claim no certificate unless it is current, and we provide it on request.
We review our controls against the National Cybersecurity Authority Essential Controls (NCA ECC), and document the gaps and the plan to close them.
We encrypt data in transit and at rest, and manage keys and access with strict role-based controls.
We run penetration tests and vulnerability scanning on a schedule we review, and remediate high-severity findings before release.
Threat model review for every new feature before implementation.
Code review before merge, alongside automated security scanning.
Unit + integration + DAST tests before production deployment.
Security alert monitoring and response under documented procedures.
A documented response plan with periodic drills.
We welcome security researchers. If you discover a vulnerability, please contact us at:
[email protected]We commit to responding within 48 hours. We follow a no-prosecution policy for good-faith researchers.
Send details to [email protected] with steps to reproduce and impact. We commit to respond within 48 hours.
Yes. Data is encrypted in transit and at rest, and access is restricted by role-based permissions.
We run penetration tests and vulnerability scanning on a periodic schedule we review, and remediate high-severity findings.