Security & Compliance

Security, data, and who owns what

We are a small senior studio, not an enterprise vendor with a certification wall. So instead of a badge grid, here is plainly how we hold data, where things run, and what you own — including the parts where the honest answer is "we do not do that".

Last reviewed 18 August 2026

You own it, start to finish

Not a policy written for this page — it is how every engagement is set up.

  • Code lives in your Git organisation from the first commit. We work as invited collaborators, not as owners.
  • Cloud, database, domain and third-party accounts are created under your billing and your identity. We are added to them; we do not hold them.
  • Handover includes documentation, environment setup and runbooks — not just a zip of source.
  • When an engagement ends we remove our access on request and confirm it in writing. No proprietary runtime, no licence fee, nothing you have to keep paying us for.

Where your product runs

Hosting is your decision and it stays in your name. We recommend, set up and document it — you hold the account.

  • Managed platforms — Vercel, Netlify or Cloudflare for the application; Neon, Supabase or a managed Postgres for data.
  • Your own cloud — AWS, Azure or Google Cloud when procurement or an existing estate requires it.
  • Self-hosted — a VPS or dedicated infrastructure (Hetzner, DigitalOcean, or your own hardware) when you need full control of the box.
  • Region is your call. We can pin application and database to EU regions for GDPR-scoped work, or to Australian regions for local residency.

How we handle data during a build

  • Least privilege: we ask for the narrowest access that gets the work done, and for a named owner on your side who can revoke it.
  • Secrets never enter the repository. Credentials live in the platform secret store or your password manager — not in code, tickets, or chat.
  • We develop against synthetic or anonymised data by default. If production data is genuinely required, we agree the scope in writing and time-box the access.
  • Devices used for client work run full-disk encryption, screen lock, and MFA on every shared account.

GDPR posture

  • In client work you are the controller and we act as a processor on your instructions. We will sign your DPA; if you do not have one, we will work from a standard template.
  • Sub-processors are disclosed before we introduce them into your project — including any AI model provider.
  • Where we build features that touch personal data, the access, export and deletion paths are part of the scope, not an afterthought.
  • We do not sell or share your data or your users’ data, and we do not use it to train models.

This website

The site you are reading is deliberately boring, and most of this is verifiable from the page source.

  • The contact form collects your name, email, company, how you found us, and your message. It is delivered as email through Resend to our inbox — there is no database behind it and no CRM sync.
  • No analytics, advertising or session-recording scripts are loaded. The only thing we store in your browser is a single entry recording your cookie choice.
  • Submissions are rate-limited per IP in memory to stop spam. Those addresses are never written to disk and are gone when the process restarts.
  • Retention and your rights are covered in the Privacy Policy.

What we do not claim

Better you learn this here than three weeks into procurement.

  • We are not SOC 2, ISO 27001, HIPAA or PCI-DSS certified. If your process requires a certified supplier, tell us early and we will say straight away whether we are a fit.
  • We do not run a 24/7 security operations centre. Response times and incident duties are set in the engagement contract, not promised on a marketing page.
  • We are a small senior team, not a managed service provider. What we offer is a clean setup you control — not a compliance department.

Sub-processors for this website

These are the third parties involved in running fastenteams.studio itself. Sub-processors for a client project are agreed separately and listed in that engagement.

Netlify
Hosting, CDN and edge routing for this website
Resend
Delivery of contact-form notifications by email

If this list changes, this page changes with it.

Questions, or found something?

Security questionnaires, DPAs and architecture questions go to contact@fastenteams.studio — a person answers, not a form. If you believe you have found a vulnerability in this site or in something we built, email us with "Security" in the subject line and we will acknowledge within two business days. We will not pursue good-faith research.