Security & trust

Your business data deserves deliberate protection.

Cunnectit approaches security as part of discovery, architecture, development, deployment, and support—not as a checklist added at the end of a project.

Secure by design

Controls are selected for each engagement based on data sensitivity, application exposure, hosting model, and client needs.

Confidentiality
Least privilege
Secure delivery
Recoverability

Our security principles

Practical safeguards across the software lifecycle.

The exact control set is documented in the project scope. These principles guide how we handle client information and design the systems we deliver.

Confidentiality by agreement

01

Project information is used only to deliver the agreed work. NDAs are available, and access to client materials is limited to people who need them for the engagement.

  • Project-specific confidentiality terms
  • Need-to-know access
  • No sale of client information

Purpose-limited data handling

02

We aim to request only the data required for discovery, development, testing, and support, with retention and deletion expectations agreed for sensitive projects.

  • Data minimisation
  • Controlled test data
  • Practical retention planning

Encryption and secrets

03

Production connections use HTTPS, while credentials and integration secrets are kept outside source code. Encryption at rest depends on the selected database and hosting platform.

  • TLS-protected connections
  • Environment-managed secrets
  • Secure transfer methods

Identity and access

04

Applications can be designed with authenticated access, role-based permissions, session controls, and audit information appropriate to the sensitivity of the workflow.

  • Least-privilege design
  • Role-based permissions
  • MFA-ready integrations

Secure engineering

05

Security is considered from architecture through release: input validation, server-side authorization, protected APIs, dependency maintenance, and focused testing are applied where relevant.

  • Secure coding practices
  • API and webhook validation
  • Release checks

Backup and recovery

06

Backup frequency, retention, restore testing, and recovery responsibilities are defined with the client and implemented using capabilities available in the chosen platform.

  • Documented backup scope
  • Restore planning
  • Operational handover

Secure delivery

Security decisions made in context.

An internal inventory tool, a public web application, and a financial workflow do not carry the same risks. We align controls to the system, its users, and the consequences of failure.

  1. 1

    Understand the risk

    We identify sensitive data, user roles, integrations, hosting constraints, and the business impact of failure before finalising the solution design.

  2. 2

    Design the controls

    Authentication, permissions, validation, logging, backups, and data flows are selected to match the actual project rather than added as generic promises.

  3. 3

    Build and verify

    Implementation includes focused reviews and testing for the agreed risks, with production credentials separated from development configuration.

  4. 4

    Handover responsibly

    We document deployment and operational responsibilities, remove unnecessary access, and agree how updates, incidents, and future changes will be handled.

Compliance readiness

Built around your obligations—not empty badges.

Cunnectit does not claim blanket certification under SOC 2, ISO 27001, HIPAA, or similar frameworks. When a project has specific regulatory or customer requirements, we help translate them into scope, architecture, operating controls, and evidence.

  • Data-flow and retention documentation
  • Access-control and audit requirements
  • Hosting and regional processing choices
  • Backup, recovery, and continuity planning
  • Secure API and third-party integration design
  • Client-specific policy and evidence needs

Security enquiries

Tell us what your project needs to protect.

Share your hosting, data, access, compliance, or vendor-security requirements before development begins. For a suspected security issue involving Cunnectit, contact us with clear reproduction details.

Email security enquiry