A clear technical approach

Trustworthy software starts
with clear boundaries.

We do not assume that every product uses the same security or hosting model. Access, data separation, backups and support are documented for the actual product and deployment.

Trust

Website and contact form

Layered protection for enquiries.

The controls used for this website's contact flow are evaluated separately from the security scope of each software product.

01

Server-side validation

Form fields are validated again when the request is processed, not only in the browser.

02

Bot and rate controls

Turnstile, a hidden trap field and short-lived rate limits work together to reduce automated misuse.

03

Secret separation

Service credentials are not embedded in page code and are read only from protected server-side variables.

Product-specific scope

Controls are verified for the actual product and deployment.

A capability available in one product is not presented as universal. The applicable scope is documented before delivery.

Roles and access

User roles, record visibility and administration rights are defined around the product's real workflow.

Record history

Where the workflow requires it, process and status history remains connected to the relevant business record.

Data separation

The way institution or customer data is separated depends on the architecture and hosting model and is documented in the scope.

Backup and recovery

Backup frequency, storage, recovery steps and responsibilities are defined for the selected deployment model.

Data and support principles

Questions to answer before the proposal.

Where data is stored, who can access it and how it is protected during support are clarified alongside the technical scope.

01

Purpose and lifecycle

Data purpose, access, export and deletion conditions are defined through the agreement and applicable privacy notices.

02

Support access

Support access is limited by need, duration and authority; permanent unrestricted access is not assumed.

03

Environment and service separation

Development, test and production environments, together with external services, are identified in the product's technical documentation.

Discuss the technical and data scope before the proposal.

Clarify access, hosting, backup and support boundaries for your product.