Security & Governance

Our approach to security governance, data governance and responsible platform practices. We describe our posture with restraint and do not claim certifications or capabilities we have not verified.

Our security philosophy

Security is a governance responsibility, not only a technical checklist. We approach it through policies, clear access decisions, appropriate controls and ongoing improvement.

Rather than claiming certifications we don't hold, we focus on implementing sound security practices appropriate to our operations and continuously improving our posture. Transparency about our approach is more valuable than overclaiming.

For advisory clients with specific compliance or governance needs, we help clarify requirements, responsibilities and appropriate controls within the engagement scope.

Our Commitment

  • Honest representation of our security posture
  • Appropriate controls for the systems we build
  • Clear documentation of security practices
  • Responsive handling of security concerns
  • Continuous improvement of our approach
  • Transparency with clients about capabilities

Security principles

The foundational principles that guide our security practices.

Access Governance

Role-based access controls and principle of least privilege across all systems and operations.

Security Visibility

Logging and monitoring appropriate to the systems, products and services we operate.

Policy Documentation

Clear, documented security policies and procedures that guide operational decision-making.

Platform Security

Security practices including encryption, access control, backups and appropriate review processes.

Team Awareness

Ongoing security awareness and training to ensure responsible handling of sensitive information.

Incident Readiness

Documented incident response procedures to address security events quickly and effectively.

Security practices

The specific practices that guide our own websites, products and services.

Data Protection

  • Encryption at rest and in transit
  • Regular backup procedures
  • Data classification frameworks
  • Retention and disposal policies

Access Management

  • Multi-factor authentication
  • Role-based access controls
  • Regular access reviews
  • Privileged access management

Security Practices

  • Secure product practices
  • Vulnerability management
  • Change management procedures
  • Third-party risk assessment

Governance

  • Security policy framework
  • Risk assessment processes
  • Compliance monitoring
  • Continuous improvement

Product security

Security considerations for our products.

Dwella

Our property management platform implements security controls appropriate for handling tenant and property data.

  • Encrypted data storage
  • Secure authentication
  • Role-based access
  • Audit logging

Client Engagements

For advisory engagements, we help clarify security, governance and risk requirements based on the organization's context.

  • Requirement analysis
  • Governance alignment
  • Documentation provided
  • Handover procedures

Security questions?

If you have questions about our security practices or need to discuss specific requirements for your engagement, we are happy to provide more detail.