Security & compliance
Your code and data, handled with care
We work with healthcare and retail clients whose data is sensitive and regulated. Security is built into how we engage, how we build and how we use AI.
01 / Practice
NDA-first engagement
Confidentiality starts before the first technical conversation.
- Mutual NDA signed before discovery or code access
- Business Associate Agreement signed before any PHI access (healthcare)
- Data Processing Agreement available for UK and EU clients under GDPR
- Named engineers only, with access reviewed at every change in the team
02 / Practice
Secure software development lifecycle
Security is part of how we design, build, review and ship.
- Threat modelling for new features that touch sensitive data
- Mandatory peer review on every change, including AI-assisted code
- Automated dependency, secret and static analysis scanning in CI
- OWASP Top 10 informed coding standards and security testing
- Separate environments, with production changes via pipeline only
03 / Practice
Data handling
We keep sensitive data out of places it does not need to be.
- Synthetic or de-identified data in development and test by default
- Encryption in transit (TLS 1.2+) and at rest in every environment we build
- Least-privilege access with MFA on all client systems and our own tools
- Client data stays in the client's cloud accounts and regions
- Secure deletion of data and credentials when an engagement ends
04 / Practice
Responsible use of AI tools
AI-native does not mean careless with your code or data.
- Only enterprise AI tools that do not train on client code or data
- AI tooling scoped per client, and disabled where policy requires
- No PHI or personal data in AI prompts
- Every AI-assisted change is reviewed and owned by a senior engineer
Our compliance position
HIPAA-aware and compliance-ready, stated plainly
Shaaz Technologies does not currently hold HIPAA, SOC 2 or ISO 27001 certifications or attestations. Our processes are HIPAA-aware and compliance-ready: we build and document systems so that your organization can meet its own regulatory obligations, and we are happy to complete security questionnaires and sign BAAs and DPAs.
Next step
Need a security questionnaire completed?
Book a call or send it over. We'll answer honestly and quickly, and walk your team through how we'd handle your data.
Book a call