Security
We hold your logins. Here's exactly what we do with them.
Outsourcing means giving another company access to your systems. That deserves a plain answer, not a badge wall. These are the controls we run, written so your IT lead or compliance officer can check them.
Where the work happens
- Inside your systems, under your access controls. We do not copy your data into ours.
- Company-owned, centrally managed workstations only. No personal laptops, ever.
- Our own office, with badge access to the production floor.
- No personal phones on the production floor. Lockers outside.
Who can see what
- One named account per person in each client system. No shared logins.
- Multi-factor authentication on every account that supports it.
- Least privilege: each role gets the access its procedure needs and nothing more, reviewed with you quarterly.
- Access is removed the same day someone leaves a project. You get a written confirmation.
People
- Every team member signs a confidentiality agreement before touching client work.
- Identity and background checked at hiring.
- Security training at onboarding and refreshed twice a year, with the phishing test we run ourselves.
- A named account manager who is accountable for your data handling.
Paper
- Non-disclosure agreement with every client.
- Business Associate Agreement for any work involving protected health information.
- Data processing terms on request for clients with their own compliance requirements.
- A written incident process: who we tell, how fast, and what we do next.
Machines
- Full-disk encryption, endpoint protection and automatic patching on every workstation.
- USB storage disabled. Screen capture and printing restricted by policy.
- Managed browsers with password manager; no credentials in documents or chats.
- Network segmented; production floor cannot reach guest Wi-Fi.
Don't take our word for it.
Three ways to check before you sign, and one that keeps running after.
- Video tour
- A live walk through the production floor on a video call, at a time you choose, unannounced to the floor.
- Visit
- You or your representative are welcome at our office. We'll book the meeting room.
- Questionnaire
- Send your vendor security questionnaire. We answer it honestly, including the items where the answer is "not yet".
- Ongoing
- Quarterly access review sent to you listing every account we hold in your systems, for you to confirm or cut.
Certifications, plainly.
We are not ISO 27001 certified today. The controls above are what an audit would examine, and we run them whether or not an auditor is watching. If a formal report matters to your procurement process, tell us; it changes the timeline, not the answer.
For healthcare clients we operate under a Business Associate Agreement and the HIPAA Security Rule's administrative, physical and technical safeguards as they apply to a business associate. For everyone else, the same controls apply because they are the same controls.