Loading…
Loading…
How we protect client code and data. The short version: encryption everywhere, least-privilege access, written runbooks, and a security review on every release.
Security at Codlinx is owned by our Director of Cloud & Platform. We follow a written information security policy reviewed quarterly, with controls aligned to ISO 27001 and SOC 2. Mapping evidence is available on request under NDA.
We deploy on AWS, GCP, or Vercel — whichever fits the engagement. Network segmentation, private VPCs, WAFs, and managed DDoS protection are the default. All infrastructure is defined as code (Terraform / Pulumi); manual changes are audited.
Centralised log aggregation with 90-day retention by default (extended on request). Alerting for authentication failures, privilege escalation, and anomalous activity. On-call rotations respond to security alerts within 15 minutes.
We maintain a written incident response plan. Severity 1 incidents trigger immediate notification to affected clients and a post-incident review within 5 working days. Tabletop exercises are run twice a year.
Every employee and contractor signs an NDA and completes security training on day one, with annual refreshers. Background checks are run for roles with production access.
We align with ISO 27001 and SOC 2 Type II. We support engagements with HIPAA, PCI-DSS, and GDPR requirements; the specific controls applied are documented in the Statement of Work and DPA.
Found something? Email security@codlinx.com with details and proof-of-concept. We acknowledge within 24 hours and aim to triage within 3 working days. We do not pursue researchers who act in good faith and follow responsible disclosure.
Questions? Write to legal@codlinx.com.