Skip to content
Security & confidentiality

Your code, data and accounts stay yours, and stay protected.

What we agree to in writing before a project starts, how we handle your information while we work, and the security we build into the software we deliver.

What we commit to

Four commitments, in writing.

NDA before discovery

A mutual NDA is signed before you share anything sensitive, including requirements, data samples and access. We are comfortable working from your template, and you can request ours at any time.

Written IP assignment

Intellectual property in what we build for you is assigned to you in writing, on payment. The assignment covers source code, designs, databases and documentation, and states its duration and territory explicitly.

Accounts in your name

Source repositories, hosting, domain, app store accounts and analytics are registered in your company name from day one, so you are never dependent on us to access your own systems.

Limited, named access

Access to your systems and data is given to the named people working on your project and removed when the work ends. Credentials are shared through a password manager, not by email or chat.

Data handling

  • Production data is not copied to personal devices unless you agree to it in writing
  • Test environments use sample or anonymised data wherever the work allows
  • Data is returned or securely deleted at the end of the engagement, on request
  • Subcontractors, if any, are disclosed in writing and bound by the same confidentiality terms

Security built into the software

  • Role-based access control, so each user sees only what their role requires
  • Audit logs recording who changed what, and when
  • Encrypted connections (HTTPS) and hashed passwords
  • Input validation and protection against common web attacks such as injection and cross-site scripting
  • Backups and a documented restore procedure, scoped with you at the start

If something goes wrong

  • You are told promptly, in writing, if we become aware of an incident affecting your data
  • We help investigate and fix the cause, and document what happened
  • Responsibilities for notification under laws that apply to you are agreed in the contract

A note on certifications. We do not claim certifications we do not hold. If your procurement process requires a specific standard or a security questionnaire, send it with your brief and we will answer it honestly, including where we would need to agree additional controls with you.

Working with overseas clients

Clients in the UK, EU, US, Canada, Australia and the Gulf often have their own data protection requirements, such as UK and EU GDPR, state privacy laws in the US, or PIPEDA in Canada. Where we process personal data on your behalf we are happy to sign a data processing agreement, restrict access to named staff, and build consent, retention and data-export features into the software. See our market pages for the rules that apply in your country.

Start a project

Need an NDA before we talk?

Send your NDA, or ask for ours, through the contact form. We will sign before you share anything sensitive.

  • Written scope before any payment
  • Fixed price, no hourly surprises
  • You own the code and accounts
  • One named project manager

Prefer to talk first?

+91 91225 05250

Mon – Sat, 10:00 AM – 7:00 PM IST