Security & access practices.

How we handle client infrastructure access, protect data, and maintain security throughout our engagements.

Infrastructure Access

  • Least-privilege access: We request only the minimum permissions required for each engagement. Assessment products use read-only access wherever possible.
  • Temporary credentials: We prefer time-limited IAM roles and avoid long-lived credentials.
  • Access documentation: We provide specific IAM policy documents before requesting access so your team can review exact permissions.
  • Prompt revocation: All access is revoked upon engagement completion. We coordinate with your team to confirm.

Data Handling

  • No data extraction: We work within your environment. We do not copy production data, customer data, or application databases.
  • Assessment outputs: Reports and deliverables contain infrastructure configuration data and recommendations, not customer or business data.
  • Confidentiality: All engagement information is treated as confidential. We sign NDAs and confidentiality agreements as standard practice.

Compliance Alignment

  • SOC 2 & ISO 27001 Readiness: We build and audit infrastructure to meet SOC 2 Type II and ISO 27001 Trust Services Criteria, ensuring audit-ready IAM access policies, CloudTrail logging, GuardDuty threat detection, and encrypted backups.
  • CIS Benchmark Hardening: We harden Kubernetes clusters and cloud accounts against CIS AWS Foundations and CIS Kubernetes Benchmarks (achieving ~98% compliance scores).
  • HIPAA & Data Privacy: For healthcare and privacy-sensitive clients, we enforce AWS KMS envelope encryption at rest, TLS 1.3 in transit, automated secret rotation, and strict VPC peering isolation.

Communication Security

  • Encrypted channels: All technical communication uses encrypted platforms (Slack, Teams, or equivalent).
  • No credentials in email: We never share credentials, tokens, or sensitive configuration via email.
  • Secure file sharing: Deliverables are shared through secure, access-controlled channels.

Engineering Practices

  • Infrastructure as Code: All infrastructure changes are made through version-controlled Terraform/Helm, never manual ClickOps.
  • Peer review: Code changes are reviewed before application.
  • Change management: Production changes follow agreed change windows and rollback procedures.
  • Audit trail: All infrastructure changes are logged and traceable.

Team Security

  • Named engineers: Every engagement has identified, named engineers. No anonymous contractors.
  • Professional credentials: Our team holds AWS, Kubernetes (CKA, CKAD, CKS), and security certifications.
  • Background: Team members have verifiable professional backgrounds in infrastructure and platform engineering.

Questions

For security-related questions or to request our standard NDA, contact: engineering@theillusio.com