Our security posture.
Last updated: August 12, 2026
Enterprise buyers ask about this before anything else. Here is exactly how we handle your data and code — no vague assurances.
1. Hosting & Infrastructure
Client applications we build are typically deployed on Vercel or your own cloud (AWS/GCP), with databases on managed providers (Neon, Supabase, or your existing infrastructure). We do not run our own unmanaged servers for client production workloads.
2. Data Handling
We access production data only when required for debugging or migration, with explicit client authorization. Credentials are stored in a password manager with per-project vaults, never in plaintext or shared documents.
3. Confidentiality & NDAs
We sign a mutual NDA before any discovery call that involves proprietary business data. Project-specific confidentiality terms are included in every Master Services Agreement.
4. Access Controls
Team access to client systems is scoped per project and revoked at engagement end. We use SSO and hardware-key 2FA internally across engineering tooling (GitHub, cloud consoles, password manager).
5. Compliance Roadmap
We are not currently SOC 2 certified. For clients that require it, we scope SOC 2 Type II readiness — policy documentation, access logging, and audit prep — as a defined workstream ahead of your compliance deadline, rather than claiming a certification we don't hold.
6. Incident Response
In the event of a security incident affecting a client system we manage, we notify the client within 24 hours of confirmation, alongside a written root-cause summary once the issue is resolved.
7. Report a Vulnerability
If you've found a security issue on this site or a NYC Digital Agency-built system, email security@nycdigital.agency. We aim to acknowledge reports within 48 hours.
