Security

How we handle security

We treat security and privacy as part of delivery, not an add-on. Before work begins, we agree what client information and system access are actually required. We use least-privilege access, keep credentials out of project files, review and record changes, and avoid retaining client data longer than the work requires. Monitoring, backups, recovery plans, and clear incident communication are matched to the system and the risks involved.

How we work

Security from planning through support.

We organize each engagement around six connected responsibilities. The safeguards we recommend are proportionate to the information, systems, people, and operational impact involved.

  1. 01
    Govern

    We define responsibilities, acceptable access, data-handling expectations, and decision points before technical work starts.

  2. 02
    Identify

    We document the systems, information, integrations, dependencies, and risks that need to be understood and protected.

  3. 03
    Protect

    We apply least-privilege access, secure credential handling, appropriate authentication, and reviewed configuration changes.

  4. 04
    Detect

    We use available logs, monitoring, and deployment records to identify unusual activity and understand what changed.

  5. 05
    Respond

    We contain the issue, preserve useful records, prioritize corrective work, and communicate known impact and next steps.

  6. 06
    Recover

    We plan backups, rollback paths, restoration, and post-recovery validation so service can return with confidence.

Reference standards

The guidance behind our work

Canadian Centre for Cyber Security

Baseline Cyber Security Controls for Small and Medium Organizations

Security guidance for small and medium organizations, including how to respond to incidents and recover.

Read the Canadian baseline

National Institute of Standards and Technology

NIST Cybersecurity Framework 2.0

A framework for assessing cybersecurity risks and organizing the work needed to address them.

Read NIST CSF 2.0

OWASP Foundation

Application Security Verification Standard 5.0.0

Testable requirements for web applications, APIs, authentication, access control, and configuration.

Read OWASP ASVS 5.0.0

We use these references to help plan and review each project. Following them does not mean that a client is certified, independently audited, or fully compliant with every requirement.

Security help

Concerned about a system, application, or upcoming change?

Get in touch