Skip to content
Security

Not an add-on. One continuous workflow.

Security starts with requirements and ownership. The necessary safeguards follow the data, risks and operating model.

Control areas

What we examine systematically in projects

ACCESS

Access

Accounts and permissions are limited to what is required. Administrative access receives additional protection and logging rules.

DEVELOPMENT

Development

Reviews, automated checks and separated environments are used in proportion to the project risk.

DEPENDENCIES

Dependencies

Libraries and services are inventoried, updated and assessed when relevant vulnerabilities emerge.

DATA

Data

Data types, purpose, storage locations, retention and deletion are documented for each project.

OPERATIONS

Operations

Monitoring, updates, backups and recovery are named operating tasks with accountable owners.

INCIDENTS

Incidents

Reporting paths, containment, communication and follow-up are prepared and practised together when appropriate.

Reports

Report a vulnerability responsibly

Do not send sensitive details through public channels. First identify the affected surface, potential impact and a secure way to contact you.

[email protected]

We acknowledge receipt, arrange a secure exchange and treat reports confidentially. The specific response time depends on severity and availability.

Start a security report
Next step

Assess security for a specific project

We classify the data, risks, responsibilities and appropriate safeguards.

Discuss security