Your idea, your code, your accounts
Working with a team in another country raises fair questions about who owns what and how safe it is. These are our answers, stated plainly.
Ownership
Everything we build for you is yours, from the first day rather than the last.
Code in your repository
We work in repositories you own. You can see every commit, and the code never lives somewhere you cannot reach.
Accounts in your name
Domain, hosting, app stores, analytics and ad accounts are created under your ownership, with us added as users.
Full handover
All files, all assets and the documented decisions behind them. You can take the product to any team.
Confidentiality
We sign a non-disclosure agreement on request, before you share anything sensitive. What you tell us in a scoping call stays with the people working on your project.
Security in the build
Every product goes through a security pass before real users or real data touch it.
Secrets kept out of the client
Keys and credentials are held in managed settings, never in browser code or source files.
Permission checks
Every route that returns data checks who is asking, so one customer cannot read another customer's records.
Validated input and rate limits
Input is checked on the server, and abuse is limited before it becomes an incident.
Integrations tested with mock transactions
Payments and third-party services are proven end to end with test orders before launch.
Separate environments
Development and production are kept apart, so testing a change cannot damage live data.
Backups and monitoring
Automated backups, logging and alerts are set up before launch, and a restore is tested.
Compliance
We build to the rules of the market your product will run in, such as GDPR and UK GDPR for personal data, HIPAA for US health data, PCI DSS for card payments and WCAG for accessibility. We tell you which apply before work starts.
We do not claim certifications we do not hold. If your procurement requires one, ask and we will answer plainly.
Commercial terms
The same three commitments apply to every build.
Milestone payments
You pay per agreed milestone, never everything up front.
Staging link by day 3
A live preview URL within the first three working days, so you see progress, not promises.
14-day bug-fix window
Anything broken in the first 14 days after launch is fixed at no charge.
Security and IP questions
Will you sign an NDA?
Yes, on request, and before you share anything sensitive. Tell us when you first get in touch and we will sign before the scoping call.
Who owns the code?
You do. Source code, repositories, domain, hosting, analytics and ad accounts are set up in your name from day one, not transferred at the end.
Do you hold ISO 27001 or SOC 2 certification?
We do not claim certifications we do not hold. If your procurement process requires a specific certification, ask us and we will tell you plainly where we stand and what we can evidence.
Can you build to GDPR or HIPAA requirements?
We build products to the rules of the market they will run in, and we say which rules apply before work starts. Compliance is a property of your product and your organisation, so we design for it and document it, and your legal adviser signs it off.
What happens to access when the project ends?
You already hold the accounts, so nothing has to be handed back. We remove our own access when you ask, and leave documentation of what was built and how it is deployed.
Need this in writing for procurement?
Tell us what your process requires and we will respond within 24 hours.
Start Building →