Skip to content

Security and trust

Your code, your data, protected by default.

This page is written for the person who has to approve us as a vendor. It covers contracts, access, secure development, data protection and what we are certifying next.

Vendor review in five days

Security questionnaires, policies and control evidence are returned within five business days. Email contact@innovation-insight.com to start.

Controls

What we do, in plain language.

Contracts and IP

  • Mutual NDA before any technical discussion
  • Full IP assignment to you on payment
  • Code, infrastructure and accounts created in your name
  • MSA and SOW with clear termination and hand-over terms

Access control

  • Least-privilege access, granted per project and revoked at exit
  • Mandatory MFA on Git, cloud and communication tools
  • Company-managed devices with full-disk encryption
  • Quarterly access reviews with written records

Secure development

  • Code review on every change, no direct pushes to main
  • Dependency and secret scanning in CI
  • OWASP Top 10 checks and security testing on releases
  • Secrets in managed vaults, never in repositories

Data protection

  • GDPR data mapping and DPA with SCCs for EU clients
  • HIPAA technical safeguards and BAA where required
  • Production data stays in your environment; masked data for development
  • Encryption in transit and at rest by default

Operations

  • Incident response plan with named owners and 24-hour client notification
  • Backups tested on a schedule
  • Monitoring and alerting on every production system we run
  • Business continuity across two offices

Certifications and roadmap

  • ISO 27001 certification in progress
  • SOC 2 control evidence available on request
  • Vendor security questionnaires completed within five business days
  • Annual third-party penetration test for hosted systems

How a vendor security review works with us

Most mid-size US and European buyers run a vendor review before signing. Ours follows the same path every time so it does not slow the project down. You send your questionnaire (SIG Lite, CAIQ, or your own template) and we return it within five business days with evidence attached: our information security policy, access control and onboarding procedures, incident response plan, backup and restore test records, and the results of our latest dependency and secret scans. If you need a Data Processing Agreement, a Business Associate Agreement or a specific NDA form, those are signed in the same window.

For regulated workloads we go a step further. Healthcare clients get a HIPAA safeguards mapping that shows which control is implemented where in the architecture; fintech clients get a PCI DSS scoping note that keeps card data out of our systems; EU clients get a data map and Standard Contractual Clauses. ISO 27001 certification is in progress, and until it is complete we share the same control evidence an auditor would see. Nothing on this page is aspirational: every control listed above is in place today on our client projects.

FAQ

Security questions, answered.

Will you sign our NDA?

Yes. Send yours, or use ours. Either way it is signed before any detailed discussion of your product.

Who owns the code you write?

You do. IP is assigned to you under the contract and the repositories are yours from the first commit.

Where is our data stored?

In your own cloud account, in the region you choose. We do not copy production data to our systems.

Are you ISO 27001 certified?

Certification is in progress. We already operate the controls and can share evidence and policies during vendor review.

How do you offboard an engineer?

Access is revoked the same day, devices are wiped, and a written hand-over covers open work and credentials rotated.