Skip to main content

Security Policy

Our commitment to protecting our clients' data and systems to the highest international standards.

Our Security Pillars

Information security controls

We use ISO 27001 requirements as the reference for building and periodically reviewing our security controls. We claim no certificate unless it is current, and we provide it on request.

Review against NCA controls

We review our controls against the National Cybersecurity Authority Essential Controls (NCA ECC), and document the gaps and the plan to close them.

Data encryption

We encrypt data in transit and at rest, and manage keys and access with strict role-based controls.

Penetration testing

We run penetration tests and vulnerability scanning on a schedule we review, and remediate high-severity findings before release.

Secure Development Lifecycle (SDLC)

  1. 01

    Secure Design

    Threat model review for every new feature before implementation.

  2. 02

    Code Review

    Code review before merge, alongside automated security scanning.

  3. 03

    Testing

    Unit + integration + DAST tests before production deployment.

  4. 04

    Monitoring

    Security alert monitoring and response under documented procedures.

  5. 05

    Incident Response

    A documented response plan with periodic drills.

Responsible Vulnerability Disclosure

We welcome security researchers. If you discover a vulnerability, please contact us at:

[email protected]

We commit to responding within 48 hours. We follow a no-prosecution policy for good-faith researchers.

Frequently Asked Questions

How do I report a security vulnerability?

Send details to [email protected] with steps to reproduce and impact. We commit to respond within 48 hours.

Is customer data encrypted?

Yes. Data is encrypted in transit and at rest, and access is restricted by role-based permissions.

How often do you run penetration tests?

We run penetration tests and vulnerability scanning on a periodic schedule we review, and remediate high-severity findings.