We build and operate systems for organisations in regulated sectors, so security has to be a property of how we work rather than a document we produce afterwards.
This page describes our general practices. Engagement-specific controls are agreed in the relevant services agreement.
How we build
Code review required before any change reaches a main branch
Dependency and static analysis scanning in the delivery pipeline
Secrets held in a managed secrets store, never in source control
Infrastructure defined as code so environments are reproducible and auditable
Access control
Least-privilege access, granted by role and reviewed periodically
Multi-factor authentication required for all internal and client systems
Individual named accounts - no shared credentials
Access revoked promptly when someone leaves a project or the company
Client data
We work in your environment and your accounts wherever possible
Production data is not copied to developer machines; anonymised or synthetic data is used for development and testing
Data residency requirements are agreed before an engagement starts
Data is returned or destroyed at the end of an engagement, as instructed
Infrastructure
Hosting on major cloud providers with encryption in transit and at rest
Logging and monitoring configured with alerting on anomalous activity
Backups taken and restore procedures tested, not assumed
Patching handled through automated pipelines rather than manual intervention
People
Background verification for staff, subject to applicable law
Confidentiality obligations in every employment and contractor agreement
Security awareness training on joining and periodically thereafter
Incident response
We maintain a documented incident response process covering identification, containment, eradication, recovery and review. Where an incident affects client data, we notify the client without undue delay and support their own notification obligations.
Reporting a vulnerability
If you believe you have found a security vulnerability in this website or in a system we operate, please email info@stratalycs.com with enough detail to reproduce it. We will acknowledge your report and keep you informed. Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.
Certifications
[List any certifications actually held, such as ISO 27001, together with scope and certification body. Remove this section entirely if none are held - do not claim certifications that are in progress.]