Security
Security practices throughout delivery.
Our delivery process covers permissions, secrets management, dependency review, monitoring, and incident responsibilities.
These are the practices we use on partner work and on Averil and LobeStack.
Security practices.
Threat modeling before features
We identify likely threats, sensitive assets, and trust boundaries early in delivery. Findings inform the requirements and release plan.
Access control first
Roles, permissions, and sensitive data paths are defined early and reviewed as the product changes.
Secrets and data separation
Secrets are kept outside the source repository. Data isolation and audit requirements are defined according to the product and its users.
Dependencies get reviewed
New packages and lockfile changes are reviewed as part of the code-review process, including packages introduced by development tools.
Monitoring before the first real user
Logging, cost tracking, alerting, and rollback requirements are defined according to the feature and its operational risk.
Incident ownership
Incident responsibilities and support contacts are documented for the delivery period and any agreed post-launch support term.
Questions.
You build with AI. Is the code safe?
We use AI-assisted development tools where they are useful, but code remains subject to engineering review and testing. Access control, data separation, dependencies, and database changes are reviewed according to the risks of the system.
Who owns the code?
Client work is maintained in a repository the client can access. Source-code ownership, third-party components, and any licensing terms are documented in the engagement agreement.
Are you SOC 2 or ISO certified?
Not today. If those letters are a procurement gate, say so on the first call. This page is the practice list we use.
Who is on call when something breaks?
During the build, the engineers on the work. After handover, your team, unless we have agreed a support stretch in writing.