Security & compliance
Before you give us access
Testing your product means touching it. Here is how we handle NDAs, access and your data — so you can decide before the first call rather than during it.
- NDA
- On request, before access
- Registered
- Estonia
- Engineers
- Ukraine, Spain, Poland, Lithuania
- Certification
- None held — see below
The four answers
What a CTO asks before granting access
Answered here so the objection is handled before the call rather than during it.
Request an NDA-
NDA on request
Ask and we sign one before any access is granted — yours or ours, whichever your legal team prefers. Most engagements start this way.
-
Access on your terms
Your VPN, your SSO, accounts you issue, or an isolated staging environment. We fit your access model rather than asking you to change it, and we ask for the least access that lets us test.
-
Your data is deleted afterwards
Test data, exports and credentials are removed at the end of an engagement unless you ask us to retain them. The same promise the free trial makes.
-
Where the team sits
Our engineers work from Ukraine, Spain, Poland and Lithuania. The company is registered in Estonia.
GDPR
Governed by the privacy policy
We process personal data in line with GDPR where it applies, and rely on Standard Contractual Clauses when data moves outside the EEA. The specifics — what we collect, why, how long we keep it and how to have it removed — live in the privacy policy, which is the document that actually governs it.
What we do not claim
We hold no formal security certification, and we would rather say so here than have you find out at diligence. If your process needs a security questionnaire filled in, send it over and we will answer it honestly, including the parts where the answer is no.
Send us a questionnaireGet started
Want the NDA first?
Ask for it before anything else — we will send one over and take it from there.