TRUST / SECURITY
How we protect your systems.
Access, secrets and data are protected by how the system is designed — not by add-ons.
- Least privilege
Users and services can only do what they are explicitly allowed to.
- Secrets out of code
Credentials never reach browsers or business tables.
- Encrypted in transit and at rest
For every system we build or run.
- Rehearsed recovery
Backups restored on a schedule defined by the engagement, not assumed.
EVIDENCE · ACCESS REVIEW · AUDIT HISTORY
LIGHT REVIEW · DARK ACTIVITY · ILLUSTRATIVE
| Identity | Role | Scope | Last used |
|---|---|---|---|
| ops@northgate | Operator | domains · DNS | 2 h ago |
| finance@northgate | Approver | orders | 3 d ago |
| svc-portal | Service | read: assets | today |
| contractor-04 | Viewer | expired | 41 d ago |
Reviewed on change and on scheduleRevoke expired
14:02:05 dns.record.updated TXT @ · ops@northgate · change #1204 ✓ 13:41:22 domain.transfer.requested northgate-holdings.co · awaiting registrar ack 11:08:10 order.approved ORD-0412 · northgate-holdings.io · 1 yr · by finance@northgate 11:07:58 order.quoted ORD-0412 · retail quote issued once 09:30:00 renewal.reminder fundcircle-capital.com · due 21 Sep 2026 · action needed 03:00:12 backup.restore-test records-db · passed · 4 m 12 s ✓
POLICIES
- 01Access reviews
Roles and service identities reviewed on change and on schedule.
- 02Change control
Every production change recorded with who, what, when.
- 03Data protection
Technical and organisational measures for information we hold or process for you.
- 04Responsible disclosure
How to report a security issue to us safely, and what we will do.
See also: Data protection · Privacy · Reliability · Responsible disclosure
NEXT STEP
Tell us what you need.
One short form. We reply with a clear next step — a call, a scoping session or a straight answer.
