01
Isolated by design.
Each client engagement runs in its own repositories, cloud accounts and credentials. Nothing is shared between clients, and access ends when the engagement does.
Booking new engagements
Security & Trust
We handle trading systems, evidence and books. Our security practice is designed for that. These are the commitments we make to every client and every user, in plain language.
Commitments
[NEED: verify each commitment against actual practice]
01
Each client engagement runs in its own repositories, cloud accounts and credentials. Nothing is shared between clients, and access ends when the engagement does.
02
Secrets and signing keys live in hardware-backed key management. Engineers use short-lived, scoped credentials, and every access is logged.
03
Client and user data is never used to train models. AI providers are contracted for zero retention where they offer it.
04
Threat modelling at design, code review on every change, dependency and secret scanning in CI, and an independent review before major releases.
05
Access is role-based, reviewed each quarter and removed on the day someone leaves. Production access requires a reason and leaves a record.
06
Written response plans, tested in drills, with customer notification commitments in every contract.
Compliance
Our controls are mapped to SOC 2 and ISO 27001, and we support clients through their own audits with evidence on request.
[NEED: actual status. Never claim certification until it is issued.]
Responsible disclosure
We welcome reports from security researchers. Email security@7s.software with details and steps to reproduce. We acknowledge every report within two business days, keep you updated and never pursue good-faith research.
[NEED: confirm address and response time]
Due diligence
We’ll share our security pack under NDA, and answer your questionnaire with the engineers who run the controls.