Security

Security and data protection

Your ERP or CRM holds your customers, prices, stock and payroll. We treat that responsibility as part of the engineering baseline: the practices below apply to every system we build, not only to those where a client asks.

What every system includes

Security is designed in from the data model onward, not bolted on before go-live.

  • Access control and 2FA

    Role-based permissions down to field level where needed, per-user accounts (no shared logins) and two-factor authentication for administrators and any remote access.

  • Encryption in transit and at rest

    TLS on every connection, encrypted database storage and encrypted backups. Secrets and API keys never travel in email, chat or spreadsheets.

  • Backups and tested restores

    Automated, versioned backups with a documented restore procedure that is actually rehearsed — a backup that has never been restored is not a backup.

  • Audit logs

    Who changed what and when is recorded for business-critical records — prices, stock adjustments, approvals, payments — and visible to authorised managers.

  • Least privilege and secret management

    Services and people get only the access they need. Credentials live in a secret manager, are rotated on hand-over and revoked when someone leaves.

  • GDPR / DSGVO-conscious data handling

    Data minimisation, defined retention, export and deletion functions and, where required, data-processing agreements. Hosting region can be chosen to match your obligations.

  • Client ownership of code and data

    Repositories, databases and hosting accounts belong to you. On hand-over you receive all credentials and documentation; our access is removed unless a support arrangement says otherwise.

What we ask of clients

Security is shared. We build the safeguards, but a system stays secure only if the people using it follow a few simple rules.

  • One account per person, never shared logins — even for busy shop-floor or counter staff.
  • Two-factor authentication enabled for owners, managers and administrators.
  • A named person on your side who approves access requests and removes accounts when someone leaves.
  • Passwords and API keys shared only through the secret manager or password tool we set up together, never over WhatsApp or email.
  • Backups kept in an account you control, and a restore test at least once a year.

Frequently asked questions

By default on managed cloud infrastructure (Cloudflare and a managed database provider) in a region agreed with you. Clients who require it can host in their own cloud account or on their own servers; the same code runs there.

Have a specific security requirement?

Bring your IT lead or auditor to the free 30-minute call and we will go through the setup in detail.