How We Protect Your Data & IP
Before any project starts, you need to know how we handle your data, code, and intellectual property. These are not afterthoughts — they are standard parts of how we work.
NDA & Confidentiality
We sign a Non-Disclosure Agreement before any sensitive business details, system architecture, or proprietary processes are discussed. If you prefer to use your own NDA template, we will review and work within it.
All team members who work on your project are bound by confidentiality obligations that extend beyond the project's completion.
IP Ownership & Code Transfer
You own everything we build. All intellectual property — including the application code, database schemas, design assets, and documentation — transfers to you in full upon final payment.
We do not retain any license to use, reproduce, or reference your code or proprietary business logic after project handover.
Code is delivered via a private Git repository that is transferred to your account at handover. You have access to the repository throughout development, not just at the end.
GDPR & Data Processing
For EU-based clients or projects that handle personal data of EU residents, we can sign a Data Processing Agreement (DPA) that specifies how personal data is processed, stored, and protected in accordance with GDPR requirements.
We do not process, store, or retain your users' personal data beyond what is required to deliver the project. Any test or demo data used during development is kept isolated and deleted after project completion.
If your project requires a specific data-residency region (e.g., EU-only hosting), we will configure deployment accordingly and document it in the project scope.
Security Practices
We follow industry-standard secure development practices on every project:
Environment variable management — secrets never hardcoded in repositories
HTTPS enforced on all production deployments; HTTP redirected automatically
Role-based access control (RBAC) enforced at the API layer, not just the UI
SQL injection and XSS prevention via parameterized queries and framework-level escaping
Dependency auditing — third-party packages reviewed for known vulnerabilities before inclusion
Staging environments are isolated from production; no production data in staging
Git history maintained with meaningful, auditable commit messages
Database backups configured on production deployments; retention period agreed upfront
Certifications & Roadmap
We are an early-stage agency with honest security practices. We do not currently hold formal third-party security certifications such as ISO 27001 or SOC 2 Type II — we will not claim them until we have earned them.
Formal certifications are on our roadmap as the company scales. If a specific certification is a hard requirement for your project, please raise it in our initial conversation — we will be direct about whether we can meet that requirement today.
Honest framing, not a gap
Every result and claim on this site is real. "Verified outcomes, no invented numbers" applies to our security posture too: we describe what we actually do, not what sounds impressive.
Payment & Financial Security
All custom projects follow a milestone-based payment structure: a deposit to start, then payments tied to delivered and reviewed milestones, with a final payment on handover. This structure keeps financial risk low for you.
We accept payment via international wire transfer, Stripe (card/bank debit), and Wise. All amounts are quoted and billed in USD unless otherwise agreed.
A cancellation policy is included in every project agreement. If a project is cancelled after work has begun, you are billed only for completed milestones; work-in-progress is handed over in its current state.
Have a Specific Security Question?
Ask us directly. We'll give you a straight answer about whether we can meet your requirements — before any commitment.
