Trust & Data Handling

Security & Data HandlingIncluding the part most vendor pages leave out.

How we handle your systems, your data and your paperwork — and an honest statement of which certifications we hold, which is none.

No production access NDA on request Your repositories

Delivered in

Client names under NDA

Posture at a glance

The answers to most of your questionnaire

Six rows that cover what a security review usually asks. If yours asks something not here, send it — an Engineer answers it, not a bid team.

Production access
Never required
We test against non-production environments. Where a finding can only be confirmed in production, we hand it to your team with reproduction detail rather than requesting access ourselves.
Production data
Never required
Test environments are seeded with masked or synthesised records that preserve the shapes which cause defects, without carrying real personal data.
Credentials
Least privilege, yours to revoke
Named accounts scoped to what the engagement needs, on your identity provider, revocable by you at any time without going through us.
Code and artefacts
Your repositories, your licence
Everything we build lives in your version control from the first commit. We do not retain copies after an engagement ends.
Paperwork
We sign yours
NDA available before you share any details. We work under your NDA, MSA and DPA rather than insisting on our own templates.
Sub-processors
None for client data
We do not pass client data to third parties. Tooling runs inside your environment or against synthetic data in ours.

What we hold, and what we do not

We hold no security certifications.

We hold no security certifications. Not SOC 2, not ISO 27001, not any other audited standard. The company was incorporated in November 2024 and has not been through a certification cycle, and we would rather write that sentence than let a procurement team infer otherwise from a page full of framework logos.

What we can tell you is how we actually work, which is set out in the table above and is the same on every engagement. Most security questionnaires we see are trying to establish two things: whether a vendor will hold your production data, and whether they can be removed cleanly. Our answers are no and yes, and both are structural rather than promises — we do not ask for production access, so there is nothing to withdraw, and everything we build is already in your repositories.

If your process requires a certified vendor, that is a legitimate requirement and we will tell you plainly that we do not meet it today rather than trying to talk you out of it.

Where the regional detail lives

Data-protection expectations differ by market, and the specifics sit on the page for each one: UK GDPR and the Data Protection Act on the United Kingdom page, the DPDP Act on the India page, the Australian Privacy Principles on the Australia page, and state-level expectations on the United States page.

Data-protection expectations differ by market, and the specifics sit on the page for each one: UK GDPR and the Data Protection Act on the United Kingdom page, the DPDP Act on the India page, the Australian Privacy Principles on the Australia page, and state-level expectations on the United States page.

The common posture does not change between them. What changes is the paperwork and, occasionally, a residency boundary — which we agree during scoping rather than discovering mid-engagement.

Accessibility, since we audit it

We sell accessibility Testing, so our own site is held to the standard we sell.

We sell accessibility Testing, so our own site is held to the standard we sell. Its current conformance status, the tooling behind that claim and the known gaps are published on the accessibility statement rather than asserted here.

Questions

Frequently Asked Questions

Straight answers, written the way we'd say them on a call.

Still curious? Talk to us

Start with a conversation

Send Us Your Security Questionnaire

An Engineer answers it, not a bid team. If we do not meet a requirement, that is what the answer will say.

  • A Senior Engineer replies, not a sales layer
  • Within one business day, every time
  • NDA available before you share any details

16+

Years QA leadership

16

Testing disciplines

6

Markets served

1

Business day to reply

Tell us where quality hurts

Prefer to talk? Book a 30-minute call