Security and compliance
Last updated 4 September 2026
Security and compliance are part of how we deliver, from the first conversation to final handover. This page summarises the controls that procurement and security teams most often ask about. Fuller documentation is available on request.
Contracts and confidentiality
Every engagement runs under a signed agreement that sets out scope, ownership, confidentiality and liability.
- Mutual NDA signed before any detailed technical conversation
- Master Services Agreement and Statements of Work, using your paper or ours
- Data Processing Agreement available for any engagement involving personal data
- Confidentiality obligations signed by every member of our team
- Non-solicitation in both directions
Vendor and security assessments
We complete security questionnaires and vendor risk assessments as part of your procurement process, including standard formats such as SIG and CAIQ as well as your own. Our controls are designed with reference to ISO/IEC 27001 and OWASP guidance, and we provide supporting evidence on request.
Code ownership and intellectual property
Your code lives in your GitHub organisation from the first commit and is deployed to your cloud account with your credentials. Intellectual property in the work we deliver is assigned to you under the contract, and we hold nothing you cannot revoke.
Access control
- Least-privilege access on every client system
- Named individual accounts, never shared logins
- Multi-factor authentication mandatory for all team members
- Access reviewed at each milestone and removed on the day an engagement ends
Secure development lifecycle
- Peer review of every change before it is merged
- Static analysis and dependency vulnerability scanning in the CI pipeline
- Secrets held in a managed vault, never committed to source code
- Development against the OWASP Top 10 and OWASP ASVS
- Security review before every major release, with support for independent penetration testing
Data protection
- Client data stays in your cloud account, in the region you choose
- Encryption in transit with TLS and at rest using platform-managed keys
- No client production data on our own machines; development uses anonymised or synthetic data
- Data returned or securely deleted at the end of an engagement, as agreed in the contract
Infrastructure and operations
- Infrastructure defined as code, with separate development, staging and production environments
- Centralised logging, monitoring and alerting
- Automated backups, restore-tested on a schedule with the results recorded
Incident response
We follow a documented incident response process. If an incident affects your systems or data, we notify you without undue delay and within the timeframe agreed in your contract, then share a written root cause analysis and remediation plan.
People and devices
- Background verification for team members before they join
- Security awareness training as part of onboarding and on an ongoing basis
- Company-managed devices with full-disk encryption and endpoint protection
- Documented knowledge and backup cover, so no engagement depends on a single person
Regulatory compliance
We build to the requirements of your regulatory framework, including the UK and EU GDPR, India's Digital Personal Data Protection Act and sector rules such as HIPAA for healthcare, and we support your audits with documentation and evidence.
AI data handling
We use enterprise API tiers, where submitted data is not used to train models. Where that is not acceptable, we run open-weight models inside your own cloud or on your own hardware. Every AI system we build has permission-aware retrieval, full audit logs, hard spending caps and per-user limits.
Reporting a vulnerability
Email info@prishora.com with the details and we will confirm receipt within one business day.