Security
We run platforms for other companies, so we are careful with access and with changes.
Access
We start with read-only access and add more only as the work needs it. In the platforms we build, people and workloads get least-privilege identities and short-lived credentials, and a log records who did what.
Changes through code
Infrastructure and configuration are written as code, and changes are reviewed before they are applied. Every change is recorded, so what runs and how it got there can be traced.
Secure defaults
Secrets are managed rather than written into code. Images and dependencies are scanned in the pipeline, networks are isolated, data is encrypted, and backups are restored in tests as well as taken.
Accounts and data
We work inside your own cloud accounts. They stay yours, and so does the data in them.
Requirements
If you have requirements to meet
If you need to meet KVKK, GDPR or the security questionnaire of your biggest customer, tell us early. We design the platform with that in mind and help you fill in the questionnaire.
See also our Security and Reliability service and our privacy policy.
What we can show you
- The code we build with, on GitHub
- How a typical assessment and onboarding run
- Reference architectures from our case studies
Questions
Ask us about security
Send a questionnaire, a requirement or a plain question. An engineer will answer within one working day.
Contact us