Data centres in the EU
System data runs in data centres in the European Union and falls under European data protection rules. Where exactly, we tell you at the conversation and write into the contract.
These are the rules we run client systems and our own by. Not promises for a contract, but what we actually do every week. If something is missing, ask at the first conversation.
System data runs in data centres in the European Union and falls under European data protection rules. Where exactly, we tell you at the conversation and write into the contract.
Only the people who work on them have access to data and systems. Passwords and keys live in a secrets manager, not in code or in emails.
The website and the systems communicate only over encrypted connections, with strict security headers. The rules that apply to our website apply to the websites and systems we build.
Data is backed up regularly. Frequency and retention are in the contract, depending on what the system does and what an outage would mean for you.
Systems are monitored automatically. We learn about an error from monitoring, not from your emails, and you see the fix in the weekly demo.
Every change is deployed automatically and verified after deployment on the real behaviour of the system, not just on the deployment having run.
If something breaks, we get in touch, not your clients. We say what happened, what it means and by when we fix it. After the fix you get a short summary so it does not repeat.
If the system processes personal data, we prepare a data processing agreement alongside the contract and a list of what is processed, where and why.
When the collaboration ends you get your data in a standard format, the domain and the brand with its rules. The handover is agreed at the start, not at the end.
Write to [email protected]. To report a security issue with the website there is also the standard security.txt file.
At the first conversation we show the monitoring, the backups and what a weekly demo looks like. Free, without commitment.