Quality & security
Engineering standards on every project
Quality and security are built into how we work, not added at the end. These are the practices we apply, whatever the size of the engagement.
Secure development
- Threats considered at design time, not after launch
- Code checked against common risk categories such as the OWASP Top 10
- Dependencies scanned and kept up to date
- Secrets kept out of source code and stored in a managed vault
Access and data protection
- Least-privilege access, individual accounts, multi-factor authentication
- Personal data minimised and handled in line with the DPDP Act, 2023
- Encryption in transit and at rest on supported platforms
- Client access removed or handed back when work ends
Testing and quality
- Peer code review on every change
- Automated tests where they protect critical behaviour
- Testing on the browsers and devices your users actually use
- Accessibility checked against WCAG 2.2 level AA for web interfaces
Reliable delivery
- Version control and automated build pipelines
- Separate development, staging and production environments
- Planned releases with a rollback path
- Monitoring, logging and alerting set up before go-live
Documentation and handover
- Architecture and deployment documentation kept current
- Runbooks for routine operations and incidents
- Source code, designs and credentials handed over to you
- Accounts created in your organisation's name
Confidentiality
- Non-disclosure agreements signed on request before any detail is shared
- Client information used only for the agreed work
- Confidential material stored in access-controlled systems
- Clear ownership of IP set out in every contract
Have something you want to build or fix?
Tell us what you are trying to achieve. We will reply with questions, options and an honest view of what it would take, whether or not we are the right fit.