Legal

Security Statement

Last updated August 1, 2026

Security is assumed, not bolted on. This statement summarises how we protect information across our work.

Our approach

We engineer as if the breach already happened: least-privilege access, defence in depth, and secure defaults. Security is part of design review, not an afterthought.

Standards we work to

We align with SOC 2 practices and adapt to the standard your domain requires, ISO 27001, HIPAA, PCI-DSS, GDPR and WCAG/508, scoped per engagement.

Reporting a vulnerability

Found something? Email us with the details and we'll acknowledge quickly and work with you on a fix. We appreciate responsible disclosure.

This document is a starting draft, have qualified counsel review it for your jurisdictions before relying on it.