Security
How we handle access to your infrastructure
We implement security controls for a living, so ours are written down here — including the honest parts about being a solo practice. If your security review needs answers beyond this page, ask: [email protected].
Read-only first
Audits run on read-only access. We request write access only for build engagements, scoped to the specific services in the statement of work.
Least privilege, your accounts
We work inside your cloud accounts and repositories through scoped IAM roles you create and you can revoke in one click. We never ask for root or owner credentials.
No stored credentials
We use short-lived, SSO-issued sessions wherever your stack supports them. We don't store long-lived client credentials, and secrets are never exchanged over email or chat — we'll set up a proper secret-sharing channel on day one.
MFA everywhere
Every ByteDel account that could touch client systems — cloud, source control, email — is protected by multi-factor authentication with hardware-backed keys.
Encrypted devices
Work happens on full-disk-encrypted machines with screen locks and automatic updates. No client data on removable media.
Your data stays yours
Deliverables live in your repos and accounts, so there's no exit migration. What we retain after an engagement is limited to the report we wrote you and standard business records.
This website
bytedel.com is a static site — it stores no client infrastructure data. What it does process: contact-form submissions (delivered to our inbox and stored in a Cloudflare D1 database so no lead is lost), newsletter emails (same database), and analytics as described in the privacy policy. The site ships with HSTS, a strict referrer policy, bot protection on forms, and is monitored for availability every 10 minutes.
Subprocessors
Cloudflare (hosting, DNS, email routing, form processing, analytics) and Google (email inbox; analytics where consented). Client engagement work uses your own cloud providers under your agreements, not ours.
Incidents and disclosure
If we discover a security issue affecting a client, we notify that client within 24 hours of confirming it, with what we know and what we're doing. Found a vulnerability in this website? Report it to [email protected] — we respond within one business day, and we won't threaten researchers acting in good faith.
The honest solo-practice answers
We don't hold a SOC 2 report ourselves — at one person, the audit would attest mostly to policies about that one person, and we'd rather show you the controls directly. We'll complete your security questionnaire, sign your NDA and DPA, and walk your security team through anything on this page live. The structural advantage of our model: because everything happens in your accounts, our access is exactly as revocable, auditable, and scoped as you make it — and we'll help you make it strict.