Security & compliance
Security that's designed in, not bolted on.
We build for regulated sectors in the UK, Europe and the UAE. Security, privacy and data residency are decided at the start of a project, not patched in before launch.
- GDPR & UK GDPR
- OWASP ASVS
- EU · UK · UAE hosting
- NDA on request
Our approach
Security starts with product decisions.
What data do you actually need? Where should it live? Who can see it, and for how long? The most important security choices are made in discovery, before a line of code is written.
We make those choices with you, write them down, and build them into the architecture, the tests and the way we operate after launch.
- 01Collect lessOnly the personal data a feature truly needs.
- 02Decide where it livesHosting region agreed at scoping, not at launch.
- 03Limit who sees itLeast-privilege access for people and agents.
Standards
Standards we build to.
We don't claim certificates we don't hold. Here is exactly how each standard shows up in our work.
- Built to
GDPR
EU data protection
Data processing agreements, privacy by design, data subject rights and records of processing on every project that handles EU personal data.
- Built to
UK GDPR
UK data protection
The same controls for UK personal data, with UK hosting available and international transfer terms where needed.
- Aligned with
OWASP ASVS
Application security
We use the Application Security Verification Standard as the checklist for authentication, sessions, access control and input handling.
- Via providers
PCI DSS
Card payments
Card data is handled by certified payment providers such as Stripe, so card numbers never touch your servers or ours.
- Aligned with
ISO 27001
Information security
Our internal practices follow ISO 27001 controls: access management, asset inventory, incident response and supplier review.
- On our roadmap
ISO 27001 & SOC 2 certification
Formal audits
Formal certification is on our roadmap. Until then we complete security questionnaires and share our policies on request.
Secure delivery lifecycle
Security across the whole lifecycle.
Five stages, each with its own checks. Nothing moves forward until the checks pass.
- 01
Discover
Map the data, the users and the risks before anything is designed.
- Data inventory
- Threat sketch
- Regulatory scope
- 02
Design
Build privacy and access control into the architecture.
- Least privilege
- Encryption plan
- Hosting region
- 03
Build
Secure coding standards, reviewed by people, checked by tools.
- Peer review
- Secret scanning
- Dependency checks
- 04
Verify
Test that the controls actually work before release.
- ASVS checklist
- Auth & access tests
- Pen test on request
- 05
Operate
Monitor, patch and respond, for as long as we look after it.
- Logging & alerts
- Patching
- Incident runbook
By sector
Standards by sector.
Every sector has its own rules. We know the common ones and work with your compliance team on the rest.
Fintech & Insurance
- PCI DSS via providers
- Strong customer authentication
- Audit trails
Healthcare
- Special category data
- Consent records
- Clinical data minimisation
Real Estate
- KYC / AML workflows
- Document retention
- Tenant data rights
E-commerce & Retail
- PCI DSS via providers
- Cookie consent
- Fraud controls
Logistics
- Driver & location data
- Role-based access
- Partner API security
Hospitality & Travel
- Guest data retention
- Payment tokenisation
- Multi-region hosting
Contracts & data
The safeguards in every contract.
NDAs on request
We sign an NDA, ours or yours, before you share anything sensitive, usually the same day.
You own the IP
Contracts assign all IP to you. Code lives in your repositories and accounts from week one.
Data residency
Host in the EU, the UK or the UAE, agreed at scoping. We use regional cloud services to keep data where it belongs.
Access control
Named accounts, least privilege, MFA everywhere, and access removed the day someone leaves the project.
AI data handling
Business-tier AI APIs that don't train on your data, no sensitive data in prompts unless agreed, and redaction where it matters.
Incident response
A written runbook, named contacts and prompt notification if anything goes wrong.
Host your data in
- EUFrankfurt · Dublin · Paris
- UKLondon
- UAEDubai · Abu Dhabi
Procurement
Security reviews and procurement, handled.
Enterprise buyers need paperwork. We make it quick.
- 01
Security questionnaires
We complete vendor questionnaires (including SIG Lite and custom forms) with your security team.
- 02
Policies on request
Information security, access control, incident response and acceptable use policies, shared under NDA.
- 03
Data processing agreements
Standard DPAs with sub-processor lists and international transfer terms.
- 04
Architecture reviews
A walkthrough of the proposed architecture, data flows and controls with your technical team.
- 05
Third-party testing
We work with your chosen penetration testers and fix findings before launch.
- 06
Audit support
Evidence and access logs for your own audits, for the systems we build and run.
Case studies
Compliance in practice.
Projects where data residency and compliance shaped the build.
- reconcile.traxpay.internal/exceptions?status=open&sort=confidenceReconcile
Exceptions
Close 30 Sep · run 06:00 CET · 38 open
Search reference, merchant…CSVAll38Split settlement12Fee at source9Timing7Duplicate6Other4Sort: confidence3 selected€15,033.62ApproveOverrideReassignReferenceMerchant · sourceAmountReasonConfidenceAgePSP-88240Nordlicht Mode GmbH · Adyen€12,005.12Split settlement64%4hWLT-10923Kaffeerösterei Lang · PayPal−€89.90Duplicate refund22%4hSTR-55190Velo Werk Berlin · Stripe€640.00Fee at source71%4hSEPA-40188Alpen Outdoor AG · Deutsche Bank€3,118.40Timing (T+2)83%1dKLN-20471Haus & Hof Online · Klarna€1,249.99Fee at source58%4hPSP-88262Studio Feinkost · Adyen€7,402.66Split settlement76%4hSEPA-40203Brettspiel Kontor · Commerzbank€412.07FX rounding91%2dWLT-10930Grünwerk Naturkosmetik · PayPal€58.35No ledger entry12%3dPSP-88277Nordlicht Mode GmbH · Adyen€2,871.30Split settlement69%4hSTR-55204Lindenholz Möbel · Stripe€19.00Fee at source88%4h1–10 of 38Rows per page: 10Fintech & Insurance · Frankfurt, Germany
AI as a Service
A Reconciliation Agent That Closes the Books in Hours, Not Days
An AI agent that matches bank, PSP and ledger records, explains every mismatch and hands finance a clean exception queue each morning.
- transactions matched automatically
- 92%transactions matched automatically
- month-end close (down from 3 days)
- 4 hrsmonth-end close (down from 3 days)
- manual review time
- -70%manual review time
- 10:41Step 4 of 5
Your price
Photographer · £48k turnover
Syndicate 4711 at Lloyd's
£38.40 a month
or £422.40 a year, paid today
MonthlyAnnuallyYour cover
Professional indemnity£1,000,000 limit£32.20Public liability£2,000,000 limit+£6.20Equipment coverUp to £5,000 of kit+£9.80Excess £250 each claimIPT included
I've read the IPID and policy wordingContinue to payment10:41Step 5 of 5Payment
£38.40 today, then on the 14th
PayOr pay with cardCard number
4658 5820 1134 4417VISAExpiry
08 / 28CVC
•••Country
United KingdomPostcode
E8 3PHPay £38.40 and start cover12 monthly payments£38.40
Due today£38.40
Powered by stripe · Terms · Privacy
Fintech & Insurance · London, UK
Custom Development
A Broker Platform That Quotes Freelancers in Under a Minute
A quote-and-bind platform that lets UK freelancers buy professional indemnity cover online, with a dashboard for brokers to manage policies and renewals.
- average time to quote
- 52saverage time to quote
- more policies bound per month
- 3.4×more policies bound per month
- broker admin time
- -60%broker admin time
E-commerce & Retail · Canada
SEO & Growth
From Position 62 to 6: SEO That Put a CBD Store on Google's First Page
A full SEO programme for a Canadian CBD e-commerce brand: technical fixes, site structure, content and clean link building that moved its average Google position from 62 to 6.
- average Google position
- 62 → 6average Google position
- traffic
- +90%traffic
- conversions
- +95%conversions
Questions We Hear Often.
Is VAUG ISO 27001 or SOC 2 certified?
Not yet. Our practices are aligned with ISO 27001 controls and formal certification is on our roadmap. We're happy to complete your security questionnaire and share our policies under NDA.
Can you host our data in the UK, EU or UAE?
Yes. We agree the hosting region during scoping and use regional cloud services so data stays where it needs to be.
Do you send our data to AI providers?
Only when agreed, only what's needed, and only through business-tier APIs that don't train on your data. Sensitive fields can be redacted before any AI call.
Will you sign our NDA?
Yes. We'll sign yours or offer ours, usually the same day, before you share anything sensitive.
Who owns the code?
You do. IP is assigned to you in the contract, and code lives in your repositories from the first week.
Do you handle card payments?
Through certified providers such as Stripe, so card data never touches your servers. That keeps your PCI DSS scope as small as possible.
Can you support our penetration test?
Yes. We work with your chosen testers, or recommend one, and fix findings before launch.
Get in touch
Send us your security questionnaire.
Or tell us about your project. A senior lead replies within one business day, and we'll sign an NDA before you share anything sensitive.
- Free 30-minute strategy call
- NDA on request
- Proposal within 48 hours
Bring your security questions.
We'll bring the answers.
Free 30-minute call · NDA before you share anything · Security questionnaire support