Skip to content
SALES TEC LLC

Security practices for the software we build

What we do on every project, what we treat as separate scoped work, and what we do not claim.

§ 01Standard practice

Applied to every project

  • 01Role-based access with least privilege by default
  • 02Multi-factor authentication on administrative and staff access
  • 03Encryption in transit everywhere, and at rest for stored data
  • 04An audit trail on changes to sensitive records
  • 05Automated backups, with restores that are tested
  • 06Separate staging and production environments
  • 07Secrets kept out of source control
  • 08Dependency and vulnerability scanning, with updates applied on a schedule
  • 09Code review before every release
  • 10Logging and monitoring, with alerts to a named person
  • 11Client notification if we detect an incident affecting your data
  • 12Return or deletion of your data at the end of an engagement, on request
§ 02Data and hosting

Your data stays yours

Production hosting is in an account you own. We work in it with the access you grant and remove that access when the engagement ends. At the end of an engagement we return or delete your data if you ask.

We choose widely used, well-documented tools and name them in the proposal, so you know what your team or another vendor would inherit.

§ 03Incidents

If something goes wrong

If we detect an incident that affects your data, we tell you, and we help you meet any notice duties you have under law. Response targets by severity are written into any support agreement.

§ 04Frameworks

Compliance work is scoped separately

We hold no security certifications. If you need to meet a framework, we scope that work on its own and say up front which parts we can deliver.

SOC 2
We can map controls and evidence for a system we build. We do not hold a SOC 2 report ourselves.
HIPAA
Only with hosting that will sign a business associate agreement, and after a scoping review.
PCI DSS
We keep card data out of your systems by using your processor's hosted fields, which limits your PCI scope.

Contract terms and process →

Security questions

Need answers for a vendor review?

Send the questionnaire with your brief. We answer it in writing and tell you where a control is outside what we do.