We use established security and privacy frameworks to guide how systems are designed, built, and maintained. The controls applied to each project depend on its data, users, integrations, and operational risks.
Review our privacy policy or security guide for more details regarding our approach.
OWASP application security guidance
Our application review and development practices follow established OWASP guidance for common web application risks.
NIST Cybersecurity Framework
We use the NIST framework as a practical reference for identifying, protecting, detecting, responding to, and recovering from security events.
CIS Controls
Infrastructure and account safeguards are informed by prioritized CIS Controls appropriate to the size and risk of your implementation.
SOC 2-ready architecture
Systems can be designed with access control, logging, change management, and evidence collection needed to support or complete compliance programs.
Privacy-by-design principles
We minimize collection, define purpose and retention, and keep data access understandable throughout the system lifecycle. Sovereign data usage is a first-class ability of our company and is available upon request.