Security

Practical safeguards for business systems.

Security decisions are matched to the information, users, hosting environment, and risk of the project.

01

Access control

  • People receive only the access their role requires.
  • End users, administrators, and service accounts remain separate.
  • Access is reviewed when roles, staff, or project ownership change.
02

Data protection

  • Managed deployments use encryption in transit and at rest; customer-hosted controls are agreed with the customer.
  • Credentials are stored outside the source code.
  • Backups and recovery expectations are agreed before launch.
03

Launch and operation

  • Dependencies and access are reviewed before launch.
  • Monitoring and incident responsibilities are documented.
  • Additional security testing is available for sensitive systems.