How We Handle
Your Data
Straight answers on security, data handling, and confidentiality — the questions your procurement or legal team would ask before signing off.
01 — Data Handling
Data Handling & Storage
Where your data goes, how long we keep it, and who else can touch it.
Where Client Data is Stored
Project files and deliverables are stored on industry-standard cloud infrastructure — primarily Vercel (for web deployments), AWS or Supabase (for backend/database needs), and Google Drive (for shared documents and handoff assets).
Data region is US-East or EU depending on your project's compliance requirements. If you need a specific region, state it in the brief and we scope accordingly.
Data Retention After Project Completion
We retain project source files and backups for 90 days post-delivery, after which all data is purged from our systems.
If you need a specific retention window (shorter for data sensitivity, or longer for ongoing maintenance), this is defined explicitly in the Statement of Work before we begin.
Your Data is Not Repurposed — Ever
Client data is used exclusively for the contracted project. We do not:
- ×Use client data to train AI models
- ×Share client data with third parties beyond listed sub-processors
- ×Use project work as portfolio examples without explicit written permission
- ×Retain database credentials or API keys after handoff
Sub-Processor Disclosure
The following third-party tools may process client data as part of project delivery:
- VercelHosting & deployment
- AWS / SupabaseDatabase & backend infrastructure
- Google WorkspaceDocument sharing & communication
- Resend / SendGridTransactional email delivery
- Stripe / RazorpayPayment processing (if applicable)
02 — Confidentiality
Confidentiality & NDAs
We treat every client engagement as confidential by default.
Default Confidentiality
We treat every client engagement as confidential regardless of whether an NDA is signed. We do not disclose client names, project details, business logic, or technical architecture to any third party without explicit written permission.
This applies to team members, contractors brought in for specialist work, and any tools used during the project.
NDA Availability
We sign NDAs before any discovery call involving sensitive business information.
Available on request — just ask before we schedule the first call. We can also review and sign your company's standard NDA if you prefer your own template.
Request NDA03 — Compliance
Compliance & Standards
Our current compliance posture — honest, not overclaimed.
What We Follow
- GDPR-aligned data handling for any EU client data — lawful basis, data minimization, right to erasure on request
- Standard data protection practices for all projects regardless of jurisdiction
- OWASP top-10 security practices for all web systems we build
- Secure credential management — credentials stored in environment variables, never in source code
- HTTPS enforced across all deployments; SSL/TLS certificates active and monitored
Honest About What We Don't Hold
We do not currently hold formal certifications such as SOC 2 Type II, ISO 27001, or PCI DSS. We are a founder-led, hands-on delivery team — not a large enterprise with a dedicated compliance arm.
If your project has specific compliance requirements (HIPAA for healthcare, PCI for payments, FCA for financial services), we're happy to discuss what that means for the architecture and scope. We'd rather have that conversation upfront than overpromise.
04 — Ownership
Code & IP Ownership
No licensing fees. No vendor lock-in. You own what we build.
Full Code Ownership on Delivery
You own 100% of the code, assets, and systems we build for you — in full, once the project is paid in full. There are no licensing fees, no recurring IP charges, and no access restrictions after handoff.
Source Code Delivered Directly
All source code is delivered to you via Git repository or direct file transfer at project completion. We don't retain rights to resell, repurpose, or redeploy your system under any other client engagement.
Credentials & Access Fully Transferred
At handoff, all credentials — API keys, database access, hosting accounts, domain registrar access — are fully transferred to your ownership. We retain no backdoor access to anything we've built.
Plain Language
You pay us to build it. You own it. That's it.
This is spelled out in every contract we sign. If you want to review our standard ownership clause before starting, ask and we'll send it.
05 — Infrastructure
Infrastructure Reliability
For engagements where we build or host live systems on your behalf.
Hosting Provider Uptime
99.99%
Vercel / AWS SLA
Backup Frequency
Nightly
30-day retention
Incident Response
< 4h
For hosted systems on retainer
Security Patching
Active
Automated dependency updates
Infrastructure commitments are defined explicitly in the Statement of Work for each engagement. For project-based work without ongoing hosting, the above refers to the underlying provider SLAs of the platforms we deploy to.
Have a Security Questionnaire to Fill Out?
Send it over — we'll turn it around within 48 hours with written answers. No back-and-forth, no delay on your procurement timeline.