Security & Compliance
How we protect your code, data & ideas
We're a senior-led engineering team, and confidentiality and security are built into how we work, not an afterthought. Here's our current posture, stated plainly.
- Mutual NDAs as standard
- Full-disk encryption
- 2FA
- Least-privilege access
- You own all the code
Confidentiality
We sign mutual NDAs before any detailed scoping work. Our standard NDA covers your ideas, code, and business plans, and we're happy to sign yours instead.
Access & device security
- Engineers work on locked-down company laptops with full-disk encryption, password managers, and 2FA on every account.
- Least-privilege access: engineers only see the code and data they need for their tasks.
- All code goes through peer review before it ships.
- We can work inside your VPN, your AWS account, or your GitHub org so your data never leaves your perimeter.
AI & your data
- We use leading third-party AI providers (OpenAI, Anthropic, and Google) through their APIs.
- We do not train or fine-tune AI models on your data.
- For projects with sensitive data, we're happy to discuss provider choice and data-handling options on a discovery call.
IP ownership
You own 100% of the code, designs, and IP we create for you. Full ownership transfers to you, with no lock-in and no licensing games.
Data protection & privacy
How we handle personal data and site data is detailed in our policies, and we'll formalize data handling for your project on request.
- We'll sign a Data Processing Agreement (DPA) on request.
- Privacy Policy
- Terms of Service
Compliance status (honest)
We follow strong security practices, but in the interest of transparency: we do not currently hold formal certifications such as SOC 2 or ISO 27001. If your project has formal compliance requirements, let's talk through them on a discovery call and agree on what's needed.
Responsible disclosure
Found a security issue in our software? Please report it to security@mobizio.io and we'll respond promptly.