Security Policy
Access to customer systems
We access customer systems only with per-instance authorization through a channel the customer specifies. No VPN is ever left open, and every access is logged.
Password management
Stored in an organization-wide password manager, 2FA enabled on every account, and all credentials handed over to the customer at project close.
Data encryption
The disk on every installed unit is fully encrypted, internal connections use TLS, and we keep no copy of customer data on our side.
When an employee leaves
Access to every system is revoked the same day, and any customer that employee worked with is notified within 3 business days.
Breach notification
We notify the customer within 24 hours of discovering an incident, sharing what we know and what we don't — we don't wait for the investigation to finish first.
Testing the delivered system
We close unused ports, configure security updates, and hand over a configuration report alongside the system for your IT team to review.