Secure software development should be something you can check. Every practice on this page runs in production today, and we publish it so you can hold us to it.
This is how the platform serving this page is protected right now.
All traffic is encrypted in transit, with HSTS preload so browsers refuse to connect insecurely.
A strict CSP controls what can load and execute on our platform, which blocks whole classes of injection attacks.
DDoS mitigation and a web application firewall sit in front of everything we serve.
Least-privilege access across our platform: every role sees exactly what it needs and nothing more.
CI audits dependencies on every build, so known-vulnerable packages don't reach production.
Backups run automatically, so recovery is a procedure rather than a scramble.
No change reaches a main branch until a second engineer has read it and approved it.
Your code lives in your repository from day one, so it never exists only with us.
Data protection here is contractual by default, so it never depends on best effort.
We sign before you send a single document. You never have to ask for confidentiality.
For engagements involving EU personal data, we sign a GDPR data processing agreement under Art. 28 that incorporates the 2021 EU Standard Contractual Clauses.
UK clients can add the UK international data transfer addendum on top of the DPA.
Production personal data stays out of development and test environments unless your contract specifically requires it.
The full list of vendors behind our platform and what each one does. There are no hidden fourth parties.
| Subprocessor | Purpose | Region |
|---|---|---|
| Cloudflare | CDN & edge security (DDoS mitigation, WAF) | Global network |
| Amazon SES | Transactional email | EU, eu-west-3 (Paris) |
| Stripe & PayPal | Payment processing | Global |
| VPS hosting | Application hosting | On request |
Found something? Tell us. We publish a security.txt at /.well-known/security.txt, and reports reach a human fast.
We answer SIG Lite and CAIQ style questionnaires as part of any evaluation, and you can ask us about anything on this page.