Trust Center
Security & access practices.
How we handle client infrastructure access, protect data, and maintain security throughout our engagements.
Infrastructure Access
- Least-privilege access: We request only the minimum permissions required for each engagement. Assessment products use read-only access wherever possible.
- Temporary credentials: We prefer time-limited IAM roles and avoid long-lived credentials.
- Access documentation: We provide specific IAM policy documents before requesting access so your team can review exact permissions.
- Prompt revocation: All access is revoked upon engagement completion. We coordinate with your team to confirm.
Data Handling
- No data extraction: We work within your environment. We do not copy production data, customer data, or application databases.
- Assessment outputs: Reports and deliverables contain infrastructure configuration data and recommendations, not customer or business data.
- Confidentiality: All engagement information is treated as confidential. We sign NDAs and confidentiality agreements as standard practice.
Compliance Alignment
- SOC 2 & ISO 27001 Readiness: We build and audit infrastructure to meet SOC 2 Type II and ISO 27001 Trust Services Criteria, ensuring audit-ready IAM access policies, CloudTrail logging, GuardDuty threat detection, and encrypted backups.
- CIS Benchmark Hardening: We harden Kubernetes clusters and cloud accounts against CIS AWS Foundations and CIS Kubernetes Benchmarks (achieving ~98% compliance scores).
- HIPAA & Data Privacy: For healthcare and privacy-sensitive clients, we enforce AWS KMS envelope encryption at rest, TLS 1.3 in transit, automated secret rotation, and strict VPC peering isolation.
Communication Security
- Encrypted channels: All technical communication uses encrypted platforms (Slack, Teams, or equivalent).
- No credentials in email: We never share credentials, tokens, or sensitive configuration via email.
- Secure file sharing: Deliverables are shared through secure, access-controlled channels.
Engineering Practices
- Infrastructure as Code: All infrastructure changes are made through version-controlled Terraform/Helm, never manual ClickOps.
- Peer review: Code changes are reviewed before application.
- Change management: Production changes follow agreed change windows and rollback procedures.
- Audit trail: All infrastructure changes are logged and traceable.
Team Security
- Named engineers: Every engagement has identified, named engineers. No anonymous contractors.
- Professional credentials: Our team holds AWS, Kubernetes (CKA, CKAD, CKS), and security certifications.
- Background: Team members have verifiable professional backgrounds in infrastructure and platform engineering.
Questions
For security-related questions or to request our standard NDA, contact: engineering@theillusio.com