Trust and security

Where your data sits, and who can reach it.

Written for whoever has to sign this off. If something here does not meet your bar, it is better for both of us that you find out on this page than in month three.

Infrastructure

Data residency and hosting.

Hosted in Canada

Primary infrastructure is DigitalOcean's Toronto region, so data stays in Canada and under Canadian law unless an engagement specifies otherwise.

Encrypted in transit

TLS 1.2 or better, enforced. Plain HTTP redirects to HTTPS on every property.

Encrypted at rest

AES-256 on databases and volumes.

Client data processed during an engagement sits on isolated infrastructure and is never shared between engagements. It is kept for as long as the engagement needs plus whatever maintenance window we have agreed, and not longer.

Access

Least privilege, and revocation that actually happens.

  • Access to a client's systems is granted only to people actively working on that engagement
  • Credentials and secrets live in environment-isolated vaults, never in source control
  • Production deployments use different credentials from development
  • Access is revoked when an engagement ends or somebody leaves, not at the next review
  • SSH to production is key-based; password authentication is disabled

How we build

Secure by default, not by review.

Code review

Production code is reviewed before merge, with authentication, input validation and data exposure checked explicitly rather than hoped for.

Dependencies

Third-party packages are checked against known vulnerabilities, kept to as few as the job needs, and pinned in production.

Environment separation

Development, staging and production are isolated — separate credentials, separate databases, separate access.

Secrets

No keys or credentials in source control. Injected at runtime from the environment or a vault.

Standing

What we hold, and what we don't.

Operating to a framework and being certified against it are different things, and this section used to blur them. It doesn't now.

  • PIPEDA (Canada)The law we operate under

    Canadian privacy law governs our handling of personal information, and our primary infrastructure is in Canada. We have not been independently audited against it — no such certification exists for PIPEDA.

  • GDPR (EU)Standard Contractual Clauses available

    Where an engagement involves EU personal data we work to GDPR and can put SCCs in place for transfers. This describes how we operate, not a certification we hold.

  • HTTPS / TLS 1.2+Enforced everywhere

    Verifiable from outside — check any of our properties.

  • SOC 2 Type IINot held

    We are a small firm and have not been through a SOC 2 audit. If your procurement requires one, say so early and we will tell you plainly whether we can meet it rather than find out at the end.

  • ISO 27001Not held

    As above. Neither is currently in progress.

  • HIPAA (US healthcare)Per engagement

    BAAs are available for US healthcare engagements, agreed before any protected health information is touched.

Responsible disclosure

Found something? Tell us before you tell the internet.

If you think you have found a vulnerability in our systems or in something we built for a client, report it privately first. A person reads that inbox and will acknowledge within 48 hours, then work out a remediation timeline with you. We will not threaten you for reporting in good faith.

security@setosys.com

Something here not meet your bar?

Ask before you get to procurement. A straight answer about what we do and don't hold is cheaper for both of us than finding out at the end of a process.