Why is security settled before the work starts?
Giving a partner access to your systems is a risk decision before it's a technical one. Your security team needs to know where the data will go, who can reach it, what happens to it at the end, and what record will exist if an auditor, a regulator or your own board asks.
We answer those questions before the first login is created. The practices on this page apply to every engagement by default, they're written into the agreement, and each one leaves a record your team can inspect.
Security isn't a phase of our work. It's the condition every phase runs under.
How do we handle your data, and where does it live?
Data handling is agreed before any access is granted: what data the work needs, where it will be stored and processed, and who can reach it. We ask only for the data the work requires.
Your environment first
If you provide an environment, we work inside it, under your policies and your monitoring. If you don't, the work runs on TriadKube's secured cloud infrastructure, and production is set up in accounts your organization owns.
Your region, and only your region
Your data stays in the region you choose. We don't copy it to another location or into tools outside the agreed environment. Our engineers work on it where it lives.
Live data stays in production
Development and test environments never hold production data. Where realistic data is needed, we use masked or synthetic data, so a defect in a test environment exposes nothing real.
Encrypted in transit and at rest
Data is encrypted whenever it moves between systems and wherever it's stored, in every environment we build or operate for you.
Who can access your systems, and for how long?
Only named people, only with the access their role needs, and only while the engagement runs.
- Every person has an individual, named account. There are no shared logins.
- Every account is protected by multi-factor sign-in.
- Access is scoped to each role and to the systems in scope. The architecture audit runs on read-only access.
- Credentials, keys and tokens are held in a secrets manager, never in code, chat or email.
- At handover, credentials pass to your team and every TriadKube account is revoked.
Nobody on our side holds more access than their work needs, and nobody keeps it after the work is done.
Who owns the intellectual property, and when is the NDA signed?
You own what we build. Confidentiality is agreed before we see anything, and ownership is written into the contract rather than left to interpretation.
-
Confidentiality first
A non-disclosure agreement is in place before we see your systems, data or documents, with terms agreed for your engagement.
-
Ownership in the contract
The master services agreement assigns ownership of the code, configuration and documentation we produce to you.
-
Your repositories from day one
Source code lives in repositories under your organization's account from the first commit.
-
Your accounts, your name
Production infrastructure is set up in accounts your organization owns, so nothing you depend on sits in ours.
How is security built into the code we write?
Security is checked on every change, not tested once at the end. Nothing reaches production until it has passed each of these steps.
-
Security in the design
The architecture audit assesses security alongside your applications, integrations and data flows, and the target architecture addresses each risk it finds before build starts.
-
Peer review on every change
No change is merged without review by a second engineer. Reviews look at how the change handles data and access, not only at whether it works.
-
Automated scanning before release
Every build is scanned for known vulnerabilities in our code and in the third-party libraries it depends on. Findings are fixed and re-checked before release.
-
Separated environments
Development, test and production are kept apart. Production data lives only in production, and production access is limited to the people who release to it.
What record will you have of what we did?
A complete one. Every decision and every change leaves a written trail that stays with your team after we've gone.
- Every code change is linked to its review, so you can see who changed what, when, and who approved it.
- Architecture decisions are recorded with the reasoning behind them and the options considered.
- Progress, risks and decisions are reported in writing at a cadence agreed at kickoff.
- Scope changes go through a documented process, with their impact assessed before approval.
- Each phase closes with a written sign-off from your stakeholders.
- A record of who held access, to which systems, and when it was revoked is handed over with the project.
Who else will have access to your data?
No one you haven't approved.
Our own team does the work
Every engagement is staffed with at least five TriadKube people, and you meet them before the work begins.
Specialists join on the same terms
When a vetted specialist is needed, you're told before they start. They're bound by the same confidentiality terms and follow the same access rules as our own engineers.
No service sees your data without your approval
Any third-party service that would store or process your data is named to you and approved by you before it's used. Where you'd rather we use your own tools, we work in them.
Frequently asked questions about security
Will you complete our vendor security questionnaire?
Yes. Send it with your first enquiry or at any point during evaluation. A senior architect completes it, and the answers match what is written on this page and in our Security Overview.
Can you work under our own security policies?
Yes, and we prefer to. Where you provide the environment, we work inside it under your access, device and change policies, and your team keeps its own monitoring over everything we do.
What happens to our data when the engagement ends?
Credentials pass to your team and every TriadKube account is revoked. Any of your data held on TriadKube infrastructure is returned or deleted as your agreement specifies, and we confirm in writing when it's done.
How do you handle cross-border engagements?
TriadKube works with clients in India, Germany and the USA. Your data stays in the region you choose, and our engineers work on it there through named, multi-factor accounts rather than moving it to where they sit.
Can our security team speak with you before we sign?
Yes. Share the Security Overview internally, and a senior architect will walk your security, legal or procurement team through any part of it in a technical session.