Security at CodeStringers is built into how we engage, not bolted on at the end. This page summarises the controls we operate today, the partners we trust with our data and our clients' data, and how to reach us about a security issue.
1. Our approach
We treat security as part of engineering and operational hygiene, not a compliance afterthought. Each engagement starts with a conversation about the data involved, the systems it touches, and what "good" looks like for the client's risk posture. We aim for defaults that are conservative without being theatrical, and we document what we do.
2. Information-security program
We operate an internal information-security program aligned to the control families of SOC 2 and ISO/IEC 27001. The program covers governance, access control, change management, vulnerability and patch management, vendor risk, incident response, and physical and personnel security.
We have not yet completed a formal SOC 2 or ISO 27001 audit. The controls described on this page are real and in operation, but no statement here should be read as a third-party attestation or certification until we publish a report or letter from a qualified auditor. Our current roadmap is described in Section 10.
3. Identity and access
- Multi-factor authentication (MFA) is required on every business system that supports it — including email, source control, project management, cloud consoles, and password management.
- Every staff member uses an organisation-managed password manager; shared accounts and personal passwords for business systems are not permitted.
- We assign access on a least-privilege basis, scoped by role. Sensitive systems (production cloud consoles, secret stores, client production data) are restricted to the smallest set of people who need them.
- We perform periodic access reviews for sensitive systems and revoke access promptly when a role changes or a person leaves.
4. Endpoints
- All staff workstations run managed endpoint protection with regular signature and behaviour updates.
- Full-disk encryption is enforced on every workstation.
- Operating-system and browser updates are kept current; critical patches are applied promptly.
- We maintain a documented lost-or-stolen-device process that includes remote wipe, credential rotation, and notification to affected clients when applicable.
5. Code and engineering practices
- Peer code review is required for changes to production systems we operate.
- Secrets, API keys, and credentials live in a managed secret store — never in source code, screenshots, or chat.
- We use lockfiles for dependency reproducibility and monitor dependency advisory feeds for known vulnerabilities in the packages we ship.
- Development, staging, and production environments are separated; real client data is not used in development or staging without explicit written permission and documented controls.
- We use signed, auditable deployments and keep deploy logs for our own systems.
6. How we handle client engagements
- Where possible, we work inside the client's own environments (the client's cloud account, the client's source control, the client's productivity suite) so that data does not leave their perimeter.
- Every engagement is governed by a written agreement that includes confidentiality obligations and, where appropriate, a data-processing addendum (DPA).
- We follow the principle of data minimisation: we ask for the least data we need to do the work, and we delete or return it at the end of the engagement.
- We do not commingle data across clients. Each client's data and credentials are isolated.
- Subcontractors who touch client data are bound by equivalent confidentiality and security obligations to those we owe the client.
7. Sub-processors
The following third parties are used to operate our business and may, in the ordinary course, process information that touches the Site or a client engagement:
- Wix.com, Ltd. — Israel / United States. Hosting, content management, form processing, and built-in analytics for codestringers.com.
- Google LLC (Google Workspace and Google Analytics 4) — United States. Business email, document collaboration, calendaring, and aggregate Site analytics.
- GitHub, Inc. — United States. Source-control and code review for the engineering work we do.
- Zoho Corporation — United States / India. Project, CRM, and business-operations tooling.
When a client engagement requires a sub-processor outside this list, we will disclose it in the engagement agreement before any client data is processed.
8. Incident response and breach notification
We maintain an internal incident-response plan with a named owner. If we become aware of a security incident that affects systems we operate or client data we hold, we will:
- Contain and investigate without unnecessary delay.
- Notify affected clients without undue delay, in keeping with our contractual and statutory obligations (including, where applicable, EU/UK GDPR's 72-hour timeline to supervisory authorities).
- Share as much information as we reasonably can about what happened, what data was involved, and what we are doing in response — and update that picture as the investigation progresses.
- Conduct a post-incident review and apply the lessons to our controls.
9. Responsible disclosure
If you believe you have found a security vulnerability in this Site or in a system we operate, please tell us — we will work with you in good faith.
- Email security@codestringers.com with a description of the issue, the affected system or URL, steps to reproduce, and any proof-of-concept material. Please do not include sensitive personal information in your report.
- We will acknowledge your report within five business days and keep you informed as we investigate.
- We ask that you give us a reasonable window before public disclosure — by default, 90 days from your report, extendable by agreement if the fix is more complex.
- Safe-harbour. We will not pursue legal action against good-faith security research that respects privacy, avoids destruction or modification of data, does not degrade the service for others, and follows this policy. Please do not access more data than necessary to demonstrate the vulnerability, and do not exfiltrate, retain, or share data you encounter.
We do not currently operate a paid bug bounty program. We do credit researchers who report valid issues, with their permission.
10. Roadmap
We are working toward formal certification against the SOC 2 and/or ISO/IEC 27001 frameworks. When we have a third-party report or letter to share, we will publish it on this page (or make it available under NDA to clients and prospects on request). Until then, the controls described above are what we attest to, in good faith, today.
11. Contact
For security questions, vulnerability reports, or customer security questionnaires:
Security Team
CodeStringers
Santa Cruz, CA, USA
security@codestringers.com