Trust & Security
We publish what we can prove.
No badges we have not earned, no maturity we have not reached. This page tells the truth about where we are — including what we have not done yet.
Confirmed against this environment.
Encrypted in transit
All traffic is served over HTTPS with a valid, publicly-trusted certificate.
Forced HTTPS
Insecure requests are redirected to HTTPS. There is no unencrypted path.
Security headers enforced
Strict-Transport-Security, X-Content-Type-Options, and Referrer-Policy are set on responses.
Automated certificate management
Certificate issuance and renewal are automated, so encryption does not lapse.
We believe these are in place; we do not publish them as fact until inspected and evidenced.
- Encryption at rest across all relevant systems
- Multi-factor authentication coverage
- Least-privilege access review
- Backup and tested-restore coverage
- Dependency and vulnerability scanning in CI
Controls we intend to implement.
- Published vulnerability-disclosure policy (security.txt)
- Formal, documented incident-response runbook
- Centralized audit logging and monitoring dashboards
These will never appear as achieved until they actually are.
- SOC 2 — not certified
- ISO 27001 — not certified
This honesty is itself a security practice. A vendor who fakes one control will fake others. We would rather tell you exactly where we are — because that is the company you can actually trust with a system.