011. Access Control
Access to client systems and credentials is granted on a least-privilege basis, limited to the personnel actively working on an engagement, and revoked promptly when no longer needed.
Multi-factor authentication is required for access to internal systems, source control, and cloud infrastructure accounts.
022. Secure Development Practices
Code is reviewed before merging to production branches, dependencies are monitored for known vulnerabilities, and secrets are never committed to source control.
033. Data Handling
Client data is encrypted in transit using TLS, and encrypted at rest where the underlying infrastructure supports it. Data is not copied to personal devices or unmanaged storage.
044. Incident Response
In the event of a suspected security incident affecting client data or systems, we notify the affected client without undue delay and provide a written summary of the incident, impact, and remediation steps.
055. Vendor and Sub-processor Review
Third-party tools and infrastructure providers used in delivery are evaluated for their own security posture and compliance certifications before adoption.
