Trust & Security
We write custom software for firms handling their most sensitive work. It runs on SOC 2 compliant infrastructure and follows industry best practices. How it is deployed, where it runs, and who can reach what are agreed with you at scoping rather than handed down.
Everything we build runs on SOC 2 compliant cloud infrastructure, encrypted with TLS 1.3 in transit and AES-256 at rest.
Single sign-on through your identity provider, role-based access, and MFA, configured to the access rules your firm already runs.
The models we use never retain or learn from your data. Processing is ephemeral: once a request completes, the data is gone.
Security is not a feature we add at the end. It is decided while the workflow is still being scoped. These are the defaults every engagement starts from.
Software we write gets the narrowest access that lets the workflow run: the folders it needs, the systems it needs, and nothing else. Elevated permissions stay on the backend, never in the browser. When a workflow needs more reach, that is a scoping decision you make, in writing.
Some firms want the software inside their own cloud tenancy, under their own procurement and data sovereignty rules. Others would rather we host and maintain it. Both are normal. We settle it at scoping and tell you plainly which services sit in the path and where the data goes.
Partnership
Security is a partnership. We work collaboratively with firms to address specific security concerns or compliance requirements, whether it's a custom security review, a DPA, or aligning with your internal policies.
If your IT or compliance team has requirements of their own, bring them into the scoping conversation. It is far easier to build to them than to retrofit them.
Get in touch
We're happy to walk your IT and compliance teams through how a build is deployed, what it can reach, and what gets logged.
Get in touch