Security & ownership
No lock-in. Everything we build runs in your own accounts, under your own name.
What you own
Source code
Lives in a repository you own, from the first commit.
Your data
Stays in your database, in your cloud account, under your control.
Cloud accounts
Infrastructure runs in accounts you own — AWS, GCP, or Azure, whichever you choose.
Domains
Registered and held in your name, not ours.
AI / API credentials
OpenAI, Anthropic, and other API keys are held in your own accounts.
Documentation
Handed over as part of delivery, not withheld as leverage.
Security practices
- Least-privilege access — team members get access to what a task needs, not everything by default.
- Secrets kept in a secrets manager, never committed to a repository.
- Encrypted connections between services and to end users.
- Dependencies kept current and checked for known vulnerabilities.
- Regular backups for anything holding real data.
- Code review before anything ships to production.
Access control & offboarding
When an engagement ends, our access is removed on request — not left dangling. Because credentials and infrastructure live in your own accounts from the start, offboarding us doesn’t mean rebuilding anything.
An NDA is available on request before any discovery work begins, for clients who want one in place up front.