Security practices

Security practices, stated plainly.

Senda Systems is a small software consultancy. Rather than borrowing enterprise language, here is exactly how we handle access, data, and confidentiality on an engagement.

How we work

A small footprint, handled with care.

01

We build inside your systems

Senda does not operate production infrastructure that stores client or customer data. Deliverables are deployed into accounts and environments that the client owns and controls.

02

Least-privilege access

Work happens under named, project-scoped accounts with multi-factor authentication and encrypted devices. Access is granted only for the engagement and removed when it ends.

03

Confidentiality by default

We work under NDA as standard practice, share nothing about client operations without written permission, and ask clients to share only the data a workflow genuinely needs.

04

An honest compliance posture

We do not currently hold formal security certifications or audit reports, and our engagements do not require them. We are glad to complete client security questionnaires and walk through these practices in detail.

Questions welcome

Ask us exactly how your data would be handled.

Email a security question