1. Home
  2. Security

Security and data protection, in plain English

Custom software usually holds the data your business cannot afford to lose or leak. This is how we protect it while we build, and how the systems we hand over are set up to stay secure after we leave.

Your accounts, our access

Repositories, cloud hosting and third-party services are opened in your company’s name. We are invited in with named accounts and removed the day the engagement ends. Nothing important lives in an account only we control.

UK and EU hosting by default

We deploy to UK or EU regions of AWS, Azure or Google Cloud unless you decide otherwise. Where personal data has to leave the UK, we document the transfer mechanism (an adequacy decision or the UK International Data Transfer Addendum) before it happens.

Least privilege everywhere

Every person and every service gets the narrowest access that lets it do its job. Production data is not copied to laptops, and test environments use generated or anonymised data.

Secure by default in the code

We build against the OWASP Top 10: parameterised queries, output encoding, proper session handling, rate limiting on logins, and secrets kept in a managed vault, never in the code. Every change is reviewed by a second developer.

Dependencies kept current

Automated scanning flags vulnerable libraries as they are disclosed. On support plans, security patches are applied as standard, not as a change request.

Independent testing when it matters

For systems holding sensitive or regulated data we arrange an external penetration test before launch with a CREST-accredited tester, and fix what it finds before go-live.

Backups you can restore

Daily backups with point-in-time recovery for databases, stored in a separate account, and a restore test before launch. A backup nobody has restored is a hope, not a backup.

AI without training on your data

When we build AI features we use business API tiers whose terms say your content is not used to train the provider’s models, minimise what is sent, and keep a human approval step wherever a wrong answer would be costly.

Security questions

Will you sign a Data Processing Agreement?

Yes. Where we process personal data on your behalf we sign a DPA that meets Article 28 of UK GDPR, listing the sub-processors involved and where data is stored.

Will you sign our NDA before we share details?

Yes, or we can send our mutual NDA. Most clients sign one before the first detailed workshop.

Do you hold ISO 27001 or Cyber Essentials?

Not at the moment. We follow the controls they describe in how we build and operate systems, and for regulated projects we design to the standard your sector requires (for example the NHS Data Security and Protection Toolkit) and arrange independent testing. If a certification is a requirement of your procurement, tell us early and we will be straight with you about whether we fit.

Who at Fixology can see our data?

Only the people working on your project, through named accounts, for as long as they need it. Access is reviewed at the end of every project and removed when the engagement ends.

Related: how we work, what to put in a software contract, support and maintenance, contact us.

Call us Start your project