Security & Compliance
How we protect your code, data & ideas
We're a senior-led engineering team, and confidentiality and security are built into how we work — not an afterthought. Here's our current posture, stated plainly.
- Mutual NDAs as standard
- Full-disk encryption
- 2FA
- Least-privilege access
- You own all the code
Confidentiality
We sign mutual NDAs before any detailed scoping work. Our standard NDA covers your ideas, code, and business plans — and we're happy to sign yours instead.
Access & device security
- Engineers work on locked-down company laptops with full-disk encryption, password managers, and 2FA on every account.
- Least-privilege access — engineers only see the code and data they need for their tasks.
- All code goes through peer review before it ships.
- We can work inside your VPN, your AWS account, or your GitHub org so your data never leaves your perimeter.
AI & your data
- We use leading third-party AI providers — OpenAI, Anthropic, and Google — through their APIs.
- We do not train or fine-tune AI models on your data.
- For projects with sensitive data, we're happy to discuss provider choice and data-handling options on a discovery call.
IP ownership
You own 100% of the code, designs, and IP we create for you. Full ownership transfers to you — no lock-in, no licensing games.
Data protection & privacy
How we handle personal data and site data is detailed in our policies, and we'll formalize data handling for your project on request.
- We'll sign a Data Processing Agreement (DPA) on request.
- Privacy Policy
- Terms of Service
Compliance status (honest)
We follow strong security practices, but in the interest of transparency: we do not currently hold formal certifications such as SOC 2 or ISO 27001. If your project has formal compliance requirements, let's talk through them on a discovery call and agree on what's needed.
Responsible disclosure
Found a security issue in our software? Please report it to security@mobizio.io and we'll respond promptly.