Austin · Lisbon · KarachiTrust centredev@binarybreach.tech
BinaryBreach
Trust centre

Our controls are maintained through automated evidence collection wired into delivery pipelines — the same approach we implement for clients. Everything below can be substantiated on request.

ISO 27001CertifiedSOC 2 Type IIAnnualReportsUnder NDA
Security operations screen in a darkened room
Certifications

Nothing on this list is aspirational. Where a framework applies to how we work rather than a certificate we hold, it says so.

ISO 27001Information security management, certified
SOC 2 Type IIAnnual audit, report available under NDA
GDPRData processing agreements and EU-hosted options
HIPAABusiness associate agreements for US healthcare
EU AI ActClassification and conformity support
WCAG 2.2 AAVerified on every release we ship
Security posture

01

Access control

Identity-based access with short-lived credentials, hardware-backed MFA for all staff, and no standing production access. Elevation is time-boxed and logged.

02

Data handling

Client data stays in the client's environment wherever the work allows. Where it cannot, it is encrypted at rest and in transit, region-pinned, and covered by a signed processing agreement.

03

Secure development

Dependency scanning, static analysis and secret detection run on every merge. Findings above an agreed severity block the build rather than opening a ticket.

04

Incident response

A documented, rehearsed process with defined notification timelines. Game days are run quarterly against injected failures, not tabletop scenarios.

05

Business continuity

Recovery objectives are tested rather than assumed. Restore drills happen on a schedule and the results are shared with clients on request.

06

Personnel

Background checks appropriate to jurisdiction, security training on joining and annually, and access revocation completed within the hour on departure.

Partners

Partner status matters mainly for support escalation paths and early access. We remain willing to recommend against any of them.

AWSAdvanced Consulting Partner
Google CloudPremier Partner
Microsoft AzureSolutions Partner, Data & AI
AnthropicBuild Partner
DatabricksConsulting Partner
NVIDIAInception Programme
SnowflakeServices Partner
HashiCorpSystems Integrator
Documentation

Write to dev@binarybreach.tech and we will send these under NDA, usually within two working days.

  • SOC 2 Type II report (current observation window)
  • ISO 27001 certificate and statement of applicability
  • Penetration test summary (annual, third party)
  • Subprocessor list and data flow diagrams
  • Standard data processing agreement
  • Business continuity and disaster recovery plan
  • Insurance certificates (professional indemnity, cyber)

Send us the questionnaire. We complete security reviews as a matter of routine and would rather do it early than at contract stage.