Skip to main content
TRUST & SECURITY

What happens to your IP, your code, and your data when you work with us.

Straight answers to the questions serious buyers ask before they sign — no legal jargon, no hiding the details.

100% IP Ownership

Transferred immediately upon delivery with zero conditions or licensing holdbacks.

Mutual NDA Upfront

Signed prior to discovery calls where proprietary ideas or data are discussed.

Isolated Environments

Dedicated staging and production cloud infrastructure with encrypted secrets.

Senior Engineers Only

Direct codebase access limited strictly to the named team building your project.

IP Ownership

You own everything. Full stop.

Every line of code, every design file, and every piece of documentation we produce belongs to you from day one. We don’t retain rights, we don’t reuse your proprietary code on other projects, and ownership transfers on delivery — not after final payment, not with conditions attached.

Full repository transfer on GitHub/GitLab
All Figma assets and design system tokens
No vendor lock-in or proprietary runtime fees
NDA & Confidentiality

NDA before we talk specifics.

We sign a mutual NDA before the first discovery call where you share anything proprietary — your idea, your data, or your roadmap. Our engineers and designers are bound by the same confidentiality terms internally.

Standard Mutual NDA

Available immediately on booking or reviewable upon request.

Data Protection

How we handle your data

  • Strict Scope-Limited Access: We only access the systems and data required for the scope of your project — nothing more. We do not inspect unneeded internal records or secondary tables.
  • Client Cloud or Named Infrastructure: Client development data and test databases reside on dedicated, encrypted instances with trusted cloud providers (AWS, GCP, Supabase, or Vercel), or directly inside your team's own cloud organization upon request.
  • Data Retention & Deletion Policy: Upon project handoff and sign-off, all client staging credentials are revoked, and temporary development environments/local caches are purged within 14 business days.
  • Secure Engineering Workstations: Work performed on client repositories is done on company-managed devices with encrypted hard disks, strict password managers, and mandatory 2FA on all Git and deployment consoles.
Infrastructure

Hosting practices

Cloud Environments

Production deployments typically run on AWS, GCP, Vercel, or directly inside your own company cloud account.

Automated CI/CD

Repeatable GitHub Actions workflows ensure unit tests, linting, and automated Docker container builds pass before merge.

Staging & Preview

Every project has an isolated staging environment so you can test features and review live builds before anything reaches users.

Compliance Transparency

Compliance

We’re a growing studio and don’t hold formal certifications like SOC 2 or ISO 27001 yet — we’re transparent about that.

What we do guarantee is NDA-backed confidentiality, complete IP transfer on delivery, and data access limited strictly to project scope. If your project has specific compliance requirements (HIPAA, GDPR, DPDP Act India, etc.), tell us during scoping and we’ll confirm upfront whether we can architect and meet them.

Access Control

Who touches your project

  • Assigned Engineers Only: Access to your codebase, APIs, and cloud services is restricted exclusively to the specific senior engineers assigned to your sprint.
  • Per-Person Accounts & SSH Keys: We use named developer accounts with enforced SSH keys and hardware or app-based 2FA. We never use shared developer passwords.
  • Revocation at Handoff: All third-party tokens, GitHub access, and database credentials are fully relinquished to your internal team upon final handoff, unless you engage us for ongoing maintenance.

Questions before you commit?

Ask us anything about how we handle your code, data, or IP — before you sign anything.

Contact our founders