Menu

Security Built In — Not Bolted On After

We treat security and compliance as architecture decisions, not checklists. Every system we build is designed for the regulatory environment it will operate in — from the first database schema to the last API endpoint.

NDA before discovery · Full IP ownership · HIPAA · GDPR · PCI-DSS · SOC 2

Standards covered
0

Standards covered

HIPAA platforms
0+

HIPAA platforms

Critical CVE response
0h

Critical CVE response

IP ownership
0%

IP ownership

  • Mutual NDA signed before any sensitive project discussion
  • Full IP assignment on final payment — no licensing, no exceptions
  • OWASP Top 10 mitigations built into every web application
  • HIPAA, GDPR, PCI-DSS, and SOC 2 designed in from day one

NDA & IP Policy

Your Idea Is Safe From the First Conversation

Legal protections kick in before we talk specifics — and stay in place through handover. No grey areas on confidentiality, ownership, or who can touch your work.

Protection path

Five contractual layers — from the first conversation through final handover — so confidentiality and ownership are never ambiguous.

Request our NDA pack
  1. 01

    Mutual NDA

    Before discovery call

    We sign a mutual Non-Disclosure Agreement before any sensitive project discussions. This covers your concept, existing codebase, business model, client data, and financial information.

  2. 02

    IP Assignment Agreement

    On final payment

    Upon full payment, 100% of all source code, design files, documentation, and intellectual property transfers to you via a formal IP assignment agreement. No licensing fees, no ongoing dependency, no exceptions.

  3. 03

    Data Handling Agreement

    Before data access

    For projects involving personal data, we execute a Data Processing Agreement (DPA) defining our role, data handling procedures, sub-processor disclosure, and breach notification obligations.

  4. 04

    Subcontractor Prohibition

    In MSA

    We contractually commit to not subcontracting your project without explicit written consent. Your project team is disclosed by name in the contract.

  5. 05

    Code Confidentiality

    Always

    Source code, architecture documents, and technical specifications are treated as confidential client materials. Staff sign confidentiality agreements as a condition of employment.

We use our standard agreements or review and sign yours — NDAs typically execute in under 24 hours.

Security Practices

How Security Is Built Into Every Project

Security is not a phase at the end. These practices run from discovery through CI — so threats are designed out early and caught before they ship.

  • OWASP Top 10 baseline
  • CVE scan in CI
  • No secrets in code
  • 24h critical patch SLA
Architecture

Threat Modelling

We conduct a lightweight threat model at the start of every project — identifying the most likely attack vectors for your specific application type and designing mitigations into the architecture.

Baseline

OWASP Top 10 by Default

Every web application is built with OWASP Top 10 mitigations as a baseline — injection prevention, authentication hardening, IDOR prevention, CSRF protection, security headers, and dependency scanning.

Review

Secure Code Review

Senior engineers conduct code reviews with security as an explicit review criterion. Critical authentication and authorisation code is always reviewed by a second engineer before merge.

Supply chain

Dependency Scanning

Automated CVE scanning of all project dependencies via Snyk or Dependabot. Critical vulnerabilities are addressed within 24 hours, high severity within 1 week.

Credentials

Secrets Management

No secrets, API keys, or credentials in source code — ever. All secrets managed via environment variables, AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault.

Validation

Penetration Testing

For high-security projects (fintech, healthcare, enterprise), we conduct an internal application security review before launch. Third-party pen testing coordinated upon client request.

Pipeline

Security in CI/CD

SAST (Semgrep), SCA (Snyk), and container image scanning (Trivy) integrated into CI pipelines — security gates that fail the build on critical findings before deployment.

Data

Encryption Standards

All data encrypted at rest (AES-256) and in transit (TLS 1.2+ minimum, TLS 1.3 recommended). Database encryption enabled on all managed database services.

Regulated industries get the same baseline — plus controls mapped to HIPAA, GDPR, PCI-DSS, SOC 2, and more.

Compliance standards

Compliance Standards

Regulatory Standards We Build To

We design for the regime your product must satisfy — not a generic checklist. Controls are mapped into architecture, access, logging, and documentation from day one.

Healthcare (US)

HIPAA

PHI encryption, BAA execution, access controls, audit logging, breach notification procedures, and Security Rule technical safeguard implementation.

Controls mapped into architecture from day one — not bolted on for audit week.

Need a control mapping for your auditor? We document what we implement against your target framework as part of delivery.

Data handling policy

Data Handling

How We Handle Your Data

A plain-English look at what we touch, who can see it, and what happens when the project ends.

  • Named-team access only
  • No production access by default
  • Client-owned repos
  • Deleted on request

Project Source Code

Who can access: Named project team only

Stored in client-owned or CodeFlamme-managed private repositories. Access restricted to named project team members. Deleted from CodeFlamme systems on project completion unless client requests otherwise.

Client Business Information

Who can access: Covered by NDA

Covered under NDA. Never shared with third parties. Not used in marketing, case studies, or references without explicit written consent.

User / Customer Data (Production)

Who can access: Only with your written OK

We never access production data unless explicitly required for debugging, and only with client authorisation. All access is logged. We recommend sanitised test data for all development and staging environments.

Design Assets

Who can access: You own them

Stored in client-owned Figma workspace or transferred to client ownership on project completion. CodeFlamme retains no licence rights over completed design work.

Internal Communication

Who can access: Project team only

Project Slack channels, meeting recordings, and internal notes related to client projects are treated as confidential and accessible only to the project team.

Still have questions about NDA timing, IP ownership, or HIPAA? We answer them directly below.

Security FAQs

FAQ

Security & Compliance Questions

Can't find what you need? Talk directly with our team.

Book a Discovery Call

Before any sensitive information is shared — before the first detailed discovery call. We provide our standard NDA within 24 hours of initial contact, or we sign yours if you prefer.

Ready to build something powerful?

Tell us what you are building. We will respond within 24 hours with a clear, honest assessment — no pressure, no sales pitch.

NDA protected · Reply within 24 hours · No commitment required