Capital · coordination · constructionCareers

Security posture and controls

The controls the practice operates, and the state each one is in. A control marked in progress is in progress; we would rather be asked about it than have a buyer discover it during review.
Control areaStateDetail
Access control and least privilegeIn placeSingle sign-on with enforced multi-factor authentication; production access granted by role and reviewed quarterly.
Secrets managementIn placeNo secret is held in source control. Production secrets are held in a managed secret store with access logged.
Change managementIn placePeer review required on every change to production code; deployments are recorded and reversible.
Endpoint and device postureIn progressManaged disk encryption and update enforcement across the practice; rollout in progress.
Logging and monitoringIn progressCentralised logging in place for platform services; alert coverage is being extended to the full estate.
Penetration testingInput pendingScope and cadence of independent testing are being set (D-G). The date of the most recent test will be published here.
Security awareness trainingIn progressAnnual training for all practice staff; completion tracking is being formalised.

Client environments

Where we deliver into a client’s environment, the client’s controls govern and ours apply to the equipment and accounts our engineers use. Where we operate a platform on a client’s behalf, both apply and the split is recorded in the agreement rather than assumed — the same discipline described on deployment & support.

Reporting a problem

Security issues go to vulnerability disclosure, which states the scope, the acknowledgement window and what we commit to in return.