About — security

What procurement asks for, published up front.

Every enterprise deal stalls at the same questionnaire. Here are the answers, in public, before you have to ask for them.

Softrear publishes its security posture: access control and data handling practice, data residency and sub-processors, its AI-in-delivery policy, build-time security gates and a coordinated vulnerability disclosure process.

How we handle your data

  • Least-privilege access, reviewed quarterly and on every joiner or leaver.
  • Production data is not copied to laptops. Debugging happens against masked or synthetic datasets.
  • Secrets live in a managed secret store, never in the repository or in CI variables.
  • All access to client systems is logged, and the log is available to you on request.

Residency and sub-processors

  • Your data stays in the region agreed in your contract, and we do not move it without your agreement in writing.
  • We tell you before adding any sub-processor that touches client data, and the current list is available on request.
  • A signed DPA is available before first contact if your procurement needs it.
  • We do not hold client production data beyond the life of the engagement unless your contract requires it.

AI and your code

  • No client code or data is submitted to any service that trains on inputs.
  • AI assistance runs on enterprise tenancy with training disabled, confirmed in writing.
  • Security-sensitive code — authentication, authorisation, cryptography, payments — is written and reviewed by people.
  • Our full policy is published at /how-we-work/ai-in-delivery.

In the build

  • Dependency and container scanning blocking on every pull request.
  • Static analysis and secret scanning in CI.
  • Threat modelling on any feature touching money, identity or personal data.
  • Penetration test before launch on client-facing systems, remediation tracked to close.

If something goes wrong

  • Report it to hello@softrear.com and it reaches an engineer, not a queue.
  • We acknowledge a report within one business day and give a first assessment within three.
  • Coordinated disclosure: we will not take legal action against good-faith research.
  • Client notification within the timeframe your contract and your regulator require, whichever is shorter.

Need the questionnaire filled in anyway?

Send it. We will return it within three business days.

Most of it is on this page, but if your process needs the form, we would rather fill it in than argue about it.

hello@softrear.com

Tell us what’s stuck.

A senior engineer reads every one of these. If we’re not the right fit we’ll say so, and point you at someone who is.

Start the conversation

No spam, no drip sequence. A senior engineer replies within one business day.