Security posture and controls
The controls the practice operates, and the state each one is in. A control marked in progress is in progress; we would rather be asked about it than have a buyer discover it during review.
| Control area | State | Detail |
|---|---|---|
| Access control and least privilege | In place | Single sign-on with enforced multi-factor authentication; production access granted by role and reviewed quarterly. |
| Secrets management | In place | No secret is held in source control. Production secrets are held in a managed secret store with access logged. |
| Change management | In place | Peer review required on every change to production code; deployments are recorded and reversible. |
| Endpoint and device posture | In progress | Managed disk encryption and update enforcement across the practice; rollout in progress. |
| Logging and monitoring | In progress | Centralised logging in place for platform services; alert coverage is being extended to the full estate. |
| Penetration testing | Input pending | Scope and cadence of independent testing are being set (D-G). The date of the most recent test will be published here. |
| Security awareness training | In progress | Annual training for all practice staff; completion tracking is being formalised. |
Client environments
Where we deliver into a client’s environment, the client’s controls govern and ours apply to the equipment and accounts our engineers use. Where we operate a platform on a client’s behalf, both apply and the split is recorded in the agreement rather than assumed — the same discipline described on deployment & support.
Reporting a problem
Security issues go to vulnerability disclosure, which states the scope, the acknowledgement window and what we commit to in return.