Skip to content

Trust Center

Security, privacy compliance

Credentials, how we handle data, and how to request assurance materials under NDA.
ISO 27001 Information Security Management Certified
AICPA SOC for Service Organizations
MCSI Certified Cloud Penetration Tester
World's Best Workplaces 2025 — Great Place To Work
G2 Best Relationship — Summer 2026
G2 Best Usability — Summer 2026

Credentials

What these marks mean

ISO 27001

Information security management certified to ISO 27001 — policies, controls, and continuous improvement for how we handle client systems and data.

AICPA SOC for Service Organizations

AICPA SOC attestation for service organizations — independent assurance over the controls that protect client systems and data.

MCSI Certified Cloud Penetration Tester

Cloud penetration-testing credential from Mossé Cyber Security Institute (MCSI) — offensive assessment skills applied to the systems we operate and secure.

World's Best Workplaces 2025

Recognized on Fortune World's Best Workplaces™ 2025 by Great Place To Work® — how we treat people is part of how we deliver for clients.

G2 Best Relationship — Summer 2026

G2 Summer 2026 Best Relationship award — peer reviews that recognize how we partner with customers through delivery.

G2 Best Usability — Summer 2026

G2 Summer 2026 Best Usability award — peer reviews that recognize how easy our work is to adopt and operate day to day.

How we handle client data

Access to client systems and repositories is least-privilege and time-bound. We use named accounts where possible, revoke access at engagement end, and do not use client source code or production data to train models unless a written agreement explicitly allows it.

Secrets stay in agreed vaults or environment stores — not in chat logs or ticket bodies. Deliverables and working notes follow the retention terms in the statement of work.

Vendors & subprocessors

Hosting, email, and monitoring vendors that support this website are shared under NDA during diligence — not listed on the open web. Client project environments are separate and agreed per engagement.

Incident response summary

  1. Detect — monitoring, reports, and human escalation paths.
  2. Contain — isolate affected systems and revoke compromised credentials.
  3. Notify — inform affected clients promptly under contract and applicable law.
  4. Remediate — fix root cause, verify, and capture lessons in our ISMS process.

Security concerns: contact us and mark the message as a security report.

Penetration-test cadence

Systems we operate as SaaS are penetration tested on a recurring cadence, with findings tracked to remediation. Client applications we build or secure follow the testing scope agreed in the engagement — often aligned with major releases or compliance deadlines.

Verify & assurance

RFP security packet

Policies overview, cert summaries, and questionnaire support — shared under NDA.

Next step

Ready when you are.

Start with a free architecture review, or book a short call. We reply within one business day.

Credentials we hold — Trust Center

  • ISO 27001 Information Security Management Certified
  • AICPA SOC for Service Organizations
  • MCSI Certified Cloud Penetration Tester
  • World's Best Workplaces 2025 — Great Place To Work
  • G2 Best Relationship — Summer 2026
  • G2 Best Usability — Summer 2026