Security & Governance
Our approach to security governance, data governance and responsible platform practices. We describe our posture with restraint and do not claim certifications or capabilities we have not verified.
Our security philosophy
Security is a governance responsibility, not only a technical checklist. We approach it through policies, clear access decisions, appropriate controls and ongoing improvement.
Rather than claiming certifications we don't hold, we focus on implementing sound security practices appropriate to our operations and continuously improving our posture. Transparency about our approach is more valuable than overclaiming.
For advisory clients with specific compliance or governance needs, we help clarify requirements, responsibilities and appropriate controls within the engagement scope.
Our Commitment
- Honest representation of our security posture
- Appropriate controls for the systems we build
- Clear documentation of security practices
- Responsive handling of security concerns
- Continuous improvement of our approach
- Transparency with clients about capabilities
Security principles
The foundational principles that guide our security practices.
Access Governance
Role-based access controls and principle of least privilege across all systems and operations.
Security Visibility
Logging and monitoring appropriate to the systems, products and services we operate.
Policy Documentation
Clear, documented security policies and procedures that guide operational decision-making.
Platform Security
Security practices including encryption, access control, backups and appropriate review processes.
Team Awareness
Ongoing security awareness and training to ensure responsible handling of sensitive information.
Incident Readiness
Documented incident response procedures to address security events quickly and effectively.
Security practices
The specific practices that guide our own websites, products and services.
Data Protection
- Encryption at rest and in transit
- Regular backup procedures
- Data classification frameworks
- Retention and disposal policies
Access Management
- Multi-factor authentication
- Role-based access controls
- Regular access reviews
- Privileged access management
Security Practices
- Secure product practices
- Vulnerability management
- Change management procedures
- Third-party risk assessment
Governance
- Security policy framework
- Risk assessment processes
- Compliance monitoring
- Continuous improvement
Product security
Security considerations for our products.
Dwella
Our property management platform implements security controls appropriate for handling tenant and property data.
- Encrypted data storage
- Secure authentication
- Role-based access
- Audit logging
Client Engagements
For advisory engagements, we help clarify security, governance and risk requirements based on the organization's context.
- Requirement analysis
- Governance alignment
- Documentation provided
- Handover procedures
Security questions?
If you have questions about our security practices or need to discuss specific requirements for your engagement, we are happy to provide more detail.