Most of the systems we build hold something a business can't afford to lose or leak. So we work to the same standard whether a client asks about it or not — and we publish it, because you shouldn't have to take it on trust.
UK or EEA hosting, chosen before anything is built. Most cloud services default to the United States, and for many the region is fixed permanently the moment the service is created — so we decide it deliberately rather than discover it.
On most services the region is fixed the moment the service is created. Changing it later means standing up a new one and migrating the data — which is expensive and disruptive rather than impossible, and entirely avoidable by choosing first.
Every record carries the identity of the business it belongs to, and that separation is enforced by the database itself — not only by the software above it.
We test it adversarially before release: deliberately asking for another business's records, using their identifiers and every route we can think of.
Application-level separation works right up until somebody is in a hurry. Broken access control is the most common class of web vulnerability there is, and testing built around normal use rarely finds it — because nothing about normal use looks like an attack.
Documents and photographs are stored privately and reached only through short-lived links, issued after we've checked you're entitled to the file. We store the internal reference, never a web address.
Web addresses survive for years in emails, exports and other systems. A signed link expires in minutes. A small distinction that prevents a large and very common failure.
Backups run from the first day a system holds real data, and we know how much a failure could cost you and how long recovery takes. We restore from backup as an exercise before launch.
An untested backup isn't a backup. It's an assumption.
Before a system goes live we build two things that are painful to add later: a complete export of your data, and a complete deletion.
Deletion means the records, the files, and anything held in a third-party service we've connected on your behalf.
A deletion that leaves the files behind is not a deletion. Files are the part that gets missed, because they sit somewhere different from the records — which is why it has to be built rather than assumed.
Automated tooling runs on everything we build and we surface what it finds rather than filtering it. Where a system warrants it — a first go-live, a source-code handover, anything deployed inside your own infrastructure — we bring in a paid independent review before release, and you get the record of it.
Tooling is the floor, not the ceiling. Automated tools find known patterns well. What they cannot judge is whether your own rules make sense — whether this person should be able to approve that order — because nothing about it looks unusual.
Every capability described in a proposal, a contract or a security questionnaire is checked against the actual code before it's sent.
Where something depends on work that hasn't shipped, it's marked as such, and we won't issue the document until it has.
This is a rule for our benefit as much as yours. It's much easier to be straightforward at the start than to explain a gap later.
These are the questions larger clients ask during procurement.
The answers are much better prepared in advance than improvised in a meeting.
Us or anybody else. The answers will tell you most of what you need to know.
A supplier who answers these easily has thought about it. One who has to go and find out hasn't.
The first one is a call, no charge and no pitch. If there's something worth doing we'll tell you what it is and roughly what it costs. If there isn't, we'll tell you that too.