Skip to content

Security & compliance

Security that's designed in, not bolted on.

We build for regulated sectors in the UK, Europe and the UAE. Security, privacy and data residency are decided at the start of a project, not patched in before launch.

  • GDPR & UK GDPR
  • OWASP ASVS
  • EU · UK · UAE hosting
  • NDA on request

Our approach

Security starts with product decisions.

What data do you actually need? Where should it live? Who can see it, and for how long? The most important security choices are made in discovery, before a line of code is written.

We make those choices with you, write them down, and build them into the architecture, the tests and the way we operate after launch.

  1. 01Collect lessOnly the personal data a feature truly needs.
  2. 02Decide where it livesHosting region agreed at scoping, not at launch.
  3. 03Limit who sees itLeast-privilege access for people and agents.

Standards

Standards we build to. 

We don't claim certificates we don't hold. Here is exactly how each standard shows up in our work.

  • Built to

    GDPR

    EU data protection

    Data processing agreements, privacy by design, data subject rights and records of processing on every project that handles EU personal data.

  • Built to

    UK GDPR

    UK data protection

    The same controls for UK personal data, with UK hosting available and international transfer terms where needed.

  • Aligned with

    OWASP ASVS

    Application security

    We use the Application Security Verification Standard as the checklist for authentication, sessions, access control and input handling.

  • Via providers

    PCI DSS

    Card payments

    Card data is handled by certified payment providers such as Stripe, so card numbers never touch your servers or ours.

  • Aligned with

    ISO 27001

    Information security

    Our internal practices follow ISO 27001 controls: access management, asset inventory, incident response and supplier review.

  • On our roadmap

    ISO 27001 & SOC 2 certification

    Formal audits

    Formal certification is on our roadmap. Until then we complete security questionnaires and share our policies on request.

Secure delivery lifecycle

Security across the whole lifecycle. 

Five stages, each with its own checks. Nothing moves forward until the checks pass.

  1. 01

    Discover

    Map the data, the users and the risks before anything is designed.

    • Data inventory
    • Threat sketch
    • Regulatory scope
  2. 02

    Design

    Build privacy and access control into the architecture.

    • Least privilege
    • Encryption plan
    • Hosting region
  3. 03

    Build

    Secure coding standards, reviewed by people, checked by tools.

    • Peer review
    • Secret scanning
    • Dependency checks
  4. 04

    Verify

    Test that the controls actually work before release.

    • ASVS checklist
    • Auth & access tests
    • Pen test on request
  5. 05

    Operate

    Monitor, patch and respond, for as long as we look after it.

    • Logging & alerts
    • Patching
    • Incident runbook

Contracts & data

The safeguards in every contract. 

  • NDAs on request

    We sign an NDA, ours or yours, before you share anything sensitive, usually the same day.

  • You own the IP

    Contracts assign all IP to you. Code lives in your repositories and accounts from week one.

  • Data residency

    Host in the EU, the UK or the UAE, agreed at scoping. We use regional cloud services to keep data where it belongs.

  • Access control

    Named accounts, least privilege, MFA everywhere, and access removed the day someone leaves the project.

  • AI data handling

    Business-tier AI APIs that don't train on your data, no sensitive data in prompts unless agreed, and redaction where it matters.

  • Incident response

    A written runbook, named contacts and prompt notification if anything goes wrong.

Host your data in

  • EUFrankfurt · Dublin · Paris
  • UKLondon
  • UAEDubai · Abu Dhabi

Procurement

Security reviews and procurement, handled. 

Enterprise buyers need paperwork. We make it quick.

  • 01

    Security questionnaires

    We complete vendor questionnaires (including SIG Lite and custom forms) with your security team.

  • 02

    Policies on request

    Information security, access control, incident response and acceptable use policies, shared under NDA.

  • 03

    Data processing agreements

    Standard DPAs with sub-processor lists and international transfer terms.

  • 04

    Architecture reviews

    A walkthrough of the proposed architecture, data flows and controls with your technical team.

  • 05

    Third-party testing

    We work with your chosen penetration testers and fix findings before launch.

  • 06

    Audit support

    Evidence and access logs for your own audits, for the systems we build and run.

Case studies

Compliance in practice. 

Projects where data residency and compliance shaped the build.

Questions We Hear Often. 

  • Is VAUG ISO 27001 or SOC 2 certified?

    Not yet. Our practices are aligned with ISO 27001 controls and formal certification is on our roadmap. We're happy to complete your security questionnaire and share our policies under NDA.

  • Can you host our data in the UK, EU or UAE?

    Yes. We agree the hosting region during scoping and use regional cloud services so data stays where it needs to be.

  • Do you send our data to AI providers?

    Only when agreed, only what's needed, and only through business-tier APIs that don't train on your data. Sensitive fields can be redacted before any AI call.

  • Will you sign our NDA?

    Yes. We'll sign yours or offer ours, usually the same day, before you share anything sensitive.

  • Who owns the code?

    You do. IP is assigned to you in the contract, and code lives in your repositories from the first week.

  • Do you handle card payments?

    Through certified providers such as Stripe, so card data never touches your servers. That keeps your PCI DSS scope as small as possible.

  • Can you support our penetration test?

    Yes. We work with your chosen testers, or recommend one, and fix findings before launch.

Get in touch

Send us your security questionnaire.

Or tell us about your project. A senior lead replies within one business day, and we'll sign an NDA before you share anything sensitive.

  • Free 30-minute strategy call
  • NDA on request
  • Proposal within 48 hours

We reply within one business day. No spam, ever.

Bring your security questions.
We'll bring the answers.

Free 30-minute call · NDA before you share anything · Security questionnaire support