Data Security
Last updated: July 13, 2026
Role-Based Access
Access to customer and product data is restricted based on user roles, so team members only access the information necessary for their responsibilities.
Encryption in Transit
Data transmitted between clients and our systems is encrypted using industry-standard transport protocols.
Secure Credentials
Credentials and API keys are stored using environment-based configuration rather than being embedded in source code, and access to them is limited to authorised personnel and systems.
Logging
Key system and access activity is logged to support monitoring and troubleshooting.
Backup Strategy
Where we manage infrastructure on behalf of a customer, backup schedules and retention are agreed as part of project scoping and documented for that deployment.
Environment Separation
Development, testing, and production environments are kept separate to reduce the risk of test data or changes affecting live systems.
Data Minimisation
We aim to collect and retain only the data necessary to deliver the relevant product or service.
Access Review
Access permissions are periodically reviewed as part of ongoing account and project management.
Vulnerability Management
We aim to apply security updates and patches to the systems we manage in a timely manner as part of regular maintenance.
Incident Handling
In the event of a security incident affecting customer data, we aim to investigate promptly and notify affected customers in line with applicable legal requirements.
Customer Deployment Options
For certain products, deployment on customer-managed infrastructure can be discussed during project scoping, depending on the specific solution and requirements.
This page describes security practices we aim to implement. It does not represent a certification, and specific controls for a given engagement are confirmed in project documentation.