Security & data protection

Answers for the security questionnaire.

Everything your legal and IT reviewers ask before a contract — access control, data handling, subprocessors, incident response — written down instead of improvised on a call.

Vendor review — quick answersEST
Signs your DPAYes
Signs your NDA before discoveryYes
Professional liability insuranceIn force
Works in your cloud accountPreferred
Production data used for developmentNo
Client data used to train modelsNo
SOC 2 / ISO 27001 certifiedNot certified
We are a small engineering firm and hold no third-party security certification. We will not claim otherwise on a questionnaire.
How we operate

Six practices, applied on every project.

Not a policy binder nobody reads — the specific controls that decide whether a breach is possible.

01

Least-privilege access

Named individual accounts, scoped to the systems a role actually needs. No shared logins, no long-lived root keys, MFA required on every account that touches client infrastructure.

02

Your cloud, your keys

Wherever possible we build inside your cloud accounts and repositories, with our access granted by you — and revocable by you at any moment, without asking us.

03

No production data in development

Development and staging run on synthetic or anonymized data. Where a defect can only be reproduced with real records, access is time-boxed, logged and agreed in writing first.

04

Secrets never live in code

Credentials sit in a managed secret store or your provider's own vault, injected at deploy time. Repositories are scanned, and any credential that passes through us is rotated at handoff.

05

Encryption in transit and at rest

TLS everywhere, provider-managed encryption at rest for databases, object storage and backups. Backups are tested by restoring them, not by assuming they work.

06

Reviewed changes, traceable history

Every change goes through pull request review and CI before production. The audit trail of who changed what, and why, stays in your repository after we leave.

Data processing

Your data, on your terms.

Where we handle personal data on your behalf, we act as a processor under your instructions. We will sign your Data Processing Agreement, or provide ours.

Roles

You remain the controller of your users' data. We process it only to deliver the Project, only on your documented instructions, and never for our own purposes.

Subprocessors

Cloud, model and tooling providers are engaged under contract, listed on request, and changed only with notice. Engineers on your project are bound by confidentiality and named to you.

Location and transfer

You choose the region your data lives in. Where engineering access crosses borders, transfers rely on standard contractual clauses and the access controls above.

Retention and deletion

At the end of an engagement we return or delete client data on request, revoke our access and rotate any credential we held. Ask, and we confirm it in writing.

AI and model providers

For AI features we use providers whose terms exclude training on your data, and we document exactly which data leaves your system, to whom, and why — before anything is built.

If something goes wrong

Incident response, in plain steps.

No security programme prevents every incident. What matters is whether you hear about it from us, quickly, with facts.

01

Contain

Revoke affected credentials, isolate the affected system and stop the bleeding before anything else.

02

Notify you

You are told without undue delay once we confirm an incident affecting your systems or data — with what we know and what we do not.

03

Investigate

Establish scope, root cause and what data was reachable, preserving logs and evidence for your own reporting duties.

04

Write it up

A written post-mortem: timeline, cause, fix and the change that prevents a repeat. Shared with you, not filed away.

Found a vulnerability in something we built?hello@launchwe.com — Subject: SecurityWe answer, we credit you, and we do not threaten researchers.
Straight answers

What reviewers usually ask next.

If your questionnaire needs something not covered here, send it — we fill it in ourselves.

Are you SOC 2 or ISO 27001 certified?

No. We are a small firm and hold no third-party certification, and we will not imply otherwise. What we do offer is a signed DPA, insured contracts, and the controls listed on this page — verifiable in your own cloud account.

Do engineers outside the US access our systems?

Yes — that is the model, and we say so plainly. Every engineer is named to you, bound by confidentiality, and granted least-privilege access you can revoke. If your policy requires US-only access, tell us before the contract; we will either staff accordingly or decline.

Will our data end up training an AI model?

Not through us. We select providers whose terms exclude training on customer data, and every flow of data out of your system is documented before it is built.

What happens to access when the project ends?

Our accounts are removed, credentials that passed through us are rotated, and client data is returned or deleted on request. Because the work lives in your accounts, you can verify all of it yourself.

Send us the questionnaire.

NDA first if you prefer. We complete security reviews ourselves — an engineer answers, not a sales rep guessing.