Security
Security and reliability
The practices below apply to every engagement, from the free scan to a dedicated pod. The detailed version, with procedures and evidence, is available on request under NDA.
NDA before any data access
No usage history, schema or sample row is shared until a mutual NDA is signed. The free readiness scan is no exception.
Least-privilege access
Named accounts, read-only roles for scans and audits, scoped roles for builds, granted inside your identity provider and warehouse. Access is reviewed at every step of the ladder and removed when the step ends.
No production credentials outside your environment
Secrets live in your secret manager and CI, never in our laptops, chat or repositories. Work happens in your cloud accounts and your repositories, under your access control and your audit log.
Data stays where it is
Nothing is copied to a system of ours. Agents and pipelines query your warehouse in place, as the user, with the warehouse's own permissions as the last line.
Redundancy and continuity
More than one engineer knows every system we build for you, and the documentation is written so that your own team or another vendor could take over. Delivery capacity does not depend on one person.
Backups and recovery
Anything we operate for you has tested backups and a written recovery procedure with the time it takes. Backups are stored in your accounts.
Change control
Every change goes through a pull request, automated tests and review before it reaches production. Infrastructure is defined as code so changes are visible and reversible.
Monitoring and incident handling
Alerts that reach a person, a runbook for each one, and a written post-incident note for anything that affected you.
If your security team has a questionnaire, send it. We answer it in writing, under NDA, before any access is granted.
Questions for your security review?
Send the questionnaire or the questions, and we will answer in writing.