Trust & Data Handling
Security & Data HandlingIncluding the part most vendor pages leave out.
How we handle your systems, your data and your paperwork — and an honest statement of which certifications we hold, which is none.
Posture at a glance
The answers to most of your questionnaire
Six rows that cover what a security review usually asks. If yours asks something not here, send it — an Engineer answers it, not a bid team.
- Production access
- Never required
- We test against non-production environments. Where a finding can only be confirmed in production, we hand it to your team with reproduction detail rather than requesting access ourselves.
- Production data
- Never required
- Test environments are seeded with masked or synthesised records that preserve the shapes which cause defects, without carrying real personal data.
- Credentials
- Least privilege, yours to revoke
- Named accounts scoped to what the engagement needs, on your identity provider, revocable by you at any time without going through us.
- Code and artefacts
- Your repositories, your licence
- Everything we build lives in your version control from the first commit. We do not retain copies after an engagement ends.
- Paperwork
- We sign yours
- NDA available before you share any details. We work under your NDA, MSA and DPA rather than insisting on our own templates.
- Sub-processors
- None for client data
- We do not pass client data to third parties. Tooling runs inside your environment or against synthetic data in ours.
What we hold, and what we do not
We hold no security certifications.
We hold no security certifications. Not SOC 2, not ISO 27001, not any other audited standard. The company was incorporated in November 2024 and has not been through a certification cycle, and we would rather write that sentence than let a procurement team infer otherwise from a page full of framework logos.
What we can tell you is how we actually work, which is set out in the table above and is the same on every engagement. Most security questionnaires we see are trying to establish two things: whether a vendor will hold your production data, and whether they can be removed cleanly. Our answers are no and yes, and both are structural rather than promises — we do not ask for production access, so there is nothing to withdraw, and everything we build is already in your repositories.
If your process requires a certified vendor, that is a legitimate requirement and we will tell you plainly that we do not meet it today rather than trying to talk you out of it.
Where the regional detail lives
Data-protection expectations differ by market, and the specifics sit on the page for each one: UK GDPR and the Data Protection Act on the United Kingdom page, the DPDP Act on the India page, the Australian Privacy Principles on the Australia page, and state-level expectations on the United States page.
Data-protection expectations differ by market, and the specifics sit on the page for each one: UK GDPR and the Data Protection Act on the United Kingdom page, the DPDP Act on the India page, the Australian Privacy Principles on the Australia page, and state-level expectations on the United States page.
The common posture does not change between them. What changes is the paperwork and, occasionally, a residency boundary — which we agree during scoping rather than discovering mid-engagement.
Accessibility, since we audit it
We sell accessibility Testing, so our own site is held to the standard we sell.
We sell accessibility Testing, so our own site is held to the standard we sell. Its current conformance status, the tooling behind that claim and the known gaps are published on the accessibility statement rather than asserted here.
Questions
Frequently Asked Questions
Straight answers, written the way we'd say them on a call.
Still curious? Talk to usSend Us Your Security Questionnaire
An Engineer answers it, not a bid team. If we do not meet a requirement, that is what the answer will say.
- A Senior Engineer replies, not a sales layer
- Within one business day, every time
- NDA available before you share any details
16+
Years QA leadership
16
Testing disciplines
6
Markets served
1
Business day to reply
Tell us where quality hurts
Prefer to talk? Book a 30-minute call
