What you are trusting us with
If we operate your platform, we hold the technology behind a regulated business. These are the practices behind that, and the questions we expect you to ask before anyone signs anything.
How we build
Four commitments that shape every engagement, not a compliance checklist.
Least privilege by default
Every service gets its own identity and only the permissions it needs. Databases sit on private networks with no public endpoint, reachable only from the compute that must reach them.
Secrets never live in code
Credentials are generated into a managed secret store and injected at deploy time. They are not in the repository, a config file, a ticket, or anyone's shell history — including ours.
Infrastructure is written down
Everything is defined as code and version-controlled, so any change is reviewable, attributable and reversible. There is no configuration that exists only in a console or in someone's memory.
Auditability from the first commit
Log retention, encryption and access boundaries are set when a system is created, not added before an audit. Evidence you need later is a by-product of how it was built.
What stays yours
Operating your platform never means owning it. The dependency has to run one way, and you must be able to end it.
- Your license, permissions and regulatory relationships
- Your customer relationships and your brand
- Your data, in a documented format, on request and at exit
- The right to take the platform in-house, with the code and the knowledge
Ask us these before you commit
Any partner worth handing a platform to should answer these in writing. We would rather you asked early than discovered late — and if an answer is no, we would rather tell you.
- 01Which certifications do you actually hold, and which are in progress?
- 02Who are your subprocessors, and where does our data physically sit?
- 03What is your incident response commitment, and who is accountable during one?
- 04What happens to our platform, data and access if this partnership ends?
- 05What insurance is in place, and what does it cover?
Send us your diligence questionnaire
We would rather work through your security review at the start than discover a blocker three months in.
Start the conversation