Architecture and environments
Security expectations are set in design, not retrofitted. We agree segmentation, environment separation, secure configuration baselines and change control before build begins.
- Environment separation between development, test and production
- Secure configuration baselines and hardening expectations
- Network segmentation and controlled integration points
- Change control and approval routes for production impact
Data classification and residency
Where data may be stored, processed and viewed is a contracting decision as much as a technical one. Classification and approved regions are documented and applied to delivery tooling as well as the target system.
- Classification agreed per data domain in scope
- Approved hosting and processing regions confirmed in writing
- Cross-border access and transfer conditions defined
- Handling rules for test data, extracts and reporting outputs
Identity and access
Access is granted to the minimum required for the delivery task, is attributable to an individual and is reviewed on a defined cadence rather than left open for the engagement duration.
- Least-privilege access aligned to delivery role
- Named accounts with no shared credentials
- Privileged access requested, approved and time-bound
- Periodic review and prompt revocation at role change or exit
People and supplier controls
Assurance covers who is doing the work, not only what is being built. Screening, confidentiality obligations and any additional client requirements are cleared before access is issued.
- Screening appropriate to the environment and data in scope
- Confidentiality and acceptable-use obligations for all personnel
- Client-specific security requirements applied where mandated
- Sub-supplier use disclosed and controlled by agreement
Delivery assurance and evidence
Security posture is demonstrated through engagement artefacts: control decisions, access records, test evidence and issue status shared with your security stakeholders.
- Documented control decisions and accepted risks
- Security testing and remediation tracked to closure
- Logging and monitoring expectations agreed per environment
- Access and change records available for review
Incident handling and exit
Both routine and adverse events are planned for. Escalation paths, notification expectations and data return or destruction at exit are set out in the engagement contract.
- Defined escalation and notification routes
- Coordination with your incident-response process
- Data return, retention and destruction at engagement end
- Handover of documentation, credentials and control records