Home/Security & Trust
Security & Compliance

How We Handle Your Data

Straight answers on security, data handling, and confidentiality — the questions your procurement or legal team would ask before signing off.

NDA Available on Request
GDPR-Aligned Practices
100% Client IP Ownership
48h Security Q&A Turnaround

01 — Data Handling

Data Handling & Storage

Where your data goes, how long we keep it, and who else can touch it.

Where Client Data is Stored

Project files and deliverables are stored on industry-standard cloud infrastructure — primarily Vercel (for web deployments), AWS or Supabase (for backend/database needs), and Google Drive (for shared documents and handoff assets).

Data region is US-East or EU depending on your project's compliance requirements. If you need a specific region, state it in the brief and we scope accordingly.

Data Retention After Project Completion

We retain project source files and backups for 90 days post-delivery, after which all data is purged from our systems.

If you need a specific retention window (shorter for data sensitivity, or longer for ongoing maintenance), this is defined explicitly in the Statement of Work before we begin.

Your Data is Not Repurposed — Ever

Client data is used exclusively for the contracted project. We do not:

  • ×Use client data to train AI models
  • ×Share client data with third parties beyond listed sub-processors
  • ×Use project work as portfolio examples without explicit written permission
  • ×Retain database credentials or API keys after handoff

Sub-Processor Disclosure

The following third-party tools may process client data as part of project delivery:

  • VercelHosting & deployment
  • AWS / SupabaseDatabase & backend infrastructure
  • Google WorkspaceDocument sharing & communication
  • Resend / SendGridTransactional email delivery
  • Stripe / RazorpayPayment processing (if applicable)

02 — Confidentiality

Confidentiality & NDAs

We treat every client engagement as confidential by default.

Default Confidentiality

We treat every client engagement as confidential regardless of whether an NDA is signed. We do not disclose client names, project details, business logic, or technical architecture to any third party without explicit written permission.

This applies to team members, contractors brought in for specialist work, and any tools used during the project.

NDA Availability

We sign NDAs before any discovery call involving sensitive business information.

Available on request — just ask before we schedule the first call. We can also review and sign your company's standard NDA if you prefer your own template.

Request NDA

03 — Compliance

Compliance & Standards

Our current compliance posture — honest, not overclaimed.

What We Follow

  • GDPR-aligned data handling for any EU client data — lawful basis, data minimization, right to erasure on request
  • Standard data protection practices for all projects regardless of jurisdiction
  • OWASP top-10 security practices for all web systems we build
  • Secure credential management — credentials stored in environment variables, never in source code
  • HTTPS enforced across all deployments; SSL/TLS certificates active and monitored

Honest About What We Don't Hold

We do not currently hold formal certifications such as SOC 2 Type II, ISO 27001, or PCI DSS. We are a founder-led, hands-on delivery team — not a large enterprise with a dedicated compliance arm.

If your project has specific compliance requirements (HIPAA for healthcare, PCI for payments, FCA for financial services), we're happy to discuss what that means for the architecture and scope. We'd rather have that conversation upfront than overpromise.

Have a specific compliance questionnaire?Send it over — we'll review and respond in writing within 48 hours.

04 — Ownership

Code & IP Ownership

No licensing fees. No vendor lock-in. You own what we build.

Full Code Ownership on Delivery

You own 100% of the code, assets, and systems we build for you — in full, once the project is paid in full. There are no licensing fees, no recurring IP charges, and no access restrictions after handoff.

Source Code Delivered Directly

All source code is delivered to you via Git repository or direct file transfer at project completion. We don't retain rights to resell, repurpose, or redeploy your system under any other client engagement.

Credentials & Access Fully Transferred

At handoff, all credentials — API keys, database access, hosting accounts, domain registrar access — are fully transferred to your ownership. We retain no backdoor access to anything we've built.

Plain Language

You pay us to build it. You own it. That's it.

This is spelled out in every contract we sign. If you want to review our standard ownership clause before starting, ask and we'll send it.

View Full Terms

05 — Infrastructure

Infrastructure Reliability

For engagements where we build or host live systems on your behalf.

Hosting Provider Uptime

99.99%

Vercel / AWS SLA

Backup Frequency

Nightly

30-day retention

Incident Response

< 4h

For hosted systems on retainer

Security Patching

Active

Automated dependency updates

Infrastructure commitments are defined explicitly in the Statement of Work for each engagement. For project-based work without ongoing hosting, the above refers to the underlying provider SLAs of the platforms we deploy to.

Have a Security Questionnaire to Fill Out?

Send it over — we'll turn it around within 48 hours with written answers. No back-and-forth, no delay on your procurement timeline.