Security

We run platforms for other companies, so we are careful with access and with changes.

Access

We start with read-only access and add more only as the work needs it. In the platforms we build, people and workloads get least-privilege identities and short-lived credentials, and a log records who did what.

Changes through code

Infrastructure and configuration are written as code, and changes are reviewed before they are applied. Every change is recorded, so what runs and how it got there can be traced.

Secure defaults

Secrets are managed rather than written into code. Images and dependencies are scanned in the pipeline, networks are isolated, data is encrypted, and backups are restored in tests as well as taken.

Accounts and data

We work inside your own cloud accounts. They stay yours, and so does the data in them.

Requirements

If you have requirements to meet

If you need to meet KVKK, GDPR or the security questionnaire of your biggest customer, tell us early. We design the platform with that in mind and help you fill in the questionnaire.

See also our Security and Reliability service and our privacy policy.

What we can show you

  • The code we build with, on GitHub
  • How a typical assessment and onboarding run
  • Reference architectures from our case studies

Questions

Ask us about security

Send a questionnaire, a requirement or a plain question. An engineer will answer within one working day.

Contact us