Start Building →
Security, IP and ownership

Your idea, your code, your accounts

Working with a team in another country raises fair questions about who owns what and how safe it is. These are our answers, stated plainly.

Ownership

Everything we build for you is yours, from the first day rather than the last.

Code in your repository

We work in repositories you own. You can see every commit, and the code never lives somewhere you cannot reach.

Accounts in your name

Domain, hosting, app stores, analytics and ad accounts are created under your ownership, with us added as users.

Full handover

All files, all assets and the documented decisions behind them. You can take the product to any team.

Confidentiality

We sign a non-disclosure agreement on request, before you share anything sensitive. What you tell us in a scoping call stays with the people working on your project.

Security in the build

Every product goes through a security pass before real users or real data touch it.

Secrets kept out of the client

Keys and credentials are held in managed settings, never in browser code or source files.

Permission checks

Every route that returns data checks who is asking, so one customer cannot read another customer's records.

Validated input and rate limits

Input is checked on the server, and abuse is limited before it becomes an incident.

Integrations tested with mock transactions

Payments and third-party services are proven end to end with test orders before launch.

Separate environments

Development and production are kept apart, so testing a change cannot damage live data.

Backups and monitoring

Automated backups, logging and alerts are set up before launch, and a restore is tested.

Compliance

We build to the rules of the market your product will run in, such as GDPR and UK GDPR for personal data, HIPAA for US health data, PCI DSS for card payments and WCAG for accessibility. We tell you which apply before work starts.

We do not claim certifications we do not hold. If your procurement requires one, ask and we will answer plainly.

Commercial terms

The same three commitments apply to every build.

Milestone payments

You pay per agreed milestone, never everything up front.

Staging link by day 3

A live preview URL within the first three working days, so you see progress, not promises.

14-day bug-fix window

Anything broken in the first 14 days after launch is fixed at no charge.

Security and IP questions

Will you sign an NDA?

Yes, on request, and before you share anything sensitive. Tell us when you first get in touch and we will sign before the scoping call.

Who owns the code?

You do. Source code, repositories, domain, hosting, analytics and ad accounts are set up in your name from day one, not transferred at the end.

Do you hold ISO 27001 or SOC 2 certification?

We do not claim certifications we do not hold. If your procurement process requires a specific certification, ask us and we will tell you plainly where we stand and what we can evidence.

Can you build to GDPR or HIPAA requirements?

We build products to the rules of the market they will run in, and we say which rules apply before work starts. Compliance is a property of your product and your organisation, so we design for it and document it, and your legal adviser signs it off.

What happens to access when the project ends?

You already hold the accounts, so nothing has to be handed back. We remove our own access when you ask, and leave documentation of what was built and how it is deployed.

Need this in writing for procurement?

Tell us what your process requires and we will respond within 24 hours.

Start Building →