We take security seriously for client projects, credentials, and production systems. This page summarises our baseline practices; project-specific requirements can be agreed in your contract.
1. Access control
- Least-privilege access to repositories, hosting, and third-party dashboards.
- Strong passwords and multi-factor authentication where supported.
- No sharing of client credentials in plain text in public channels.
2. Development & deployment
- HTTPS for public-facing applications where we control hosting configuration.
- Dependency updates and security patches applied as part of maintenance agreements.
- Environment separation (staging vs production) where budgets allow.
3. Data handling
Sensitive data should not be emailed unencrypted when alternatives exist. We recommend vaults or secure channels for production secrets. Backups and retention follow your agreement and applicable regulations (e.g. healthcare or financial rules in your market).
4. Incident response
If a security issue affects your project, we notify you promptly and work on containment and remediation as defined in your statement of work or SLA.
5. Your responsibilities
Clients remain responsible for compliance in their industry (PCI, HIPAA-style requirements, UAE/KSA data rules, etc.), end-user policies, and legal content on their sites.
6. Contact
Security questions: hexastacksolutions@gmail.com