Security and confidentiality

Written so you can answer your own client's questions.

Agencies and consultancies get asked where the work is done, who touches the data and what happens if something goes wrong. This page is the answer, in a form you can forward. It describes what we actually do rather than what sounds reassuring.

We hold no security certification and do not claim one. Where a control is a practice rather than an audited standard, it is described as a practice. Send your security questionnaire with your enquiry and we will complete it as written.

The short answers

The six questions that arrive first.

These are the lines that appear in almost every supplier assessment. The detail behind each one is below.

Common supplier assessment questions and Insteller's position
QuestionOur position
Do you hold ISO 27001, SOC 2 or an equivalent certification?No. We hold no security certification and do not claim one. Everything on this page is a practice we run and will evidence on request.
Where does our data sit?Wherever you keep it. We work in your systems, your repositories and your cloud accounts by default, so production data stays inside your boundary.
Who has access to it?Only the named engineers on your engagement, at the access level you grant. Access is requested per person and removed when that person leaves the engagement.
Do you subcontract?No, not without written agreement. Work is delivered by people employed by Insteller. Anything else is disclosed and approved before it happens.
Will you sign our agreement?Yes. We sign your non-disclosure agreement, your data processing terms and your intellectual property assignment before an engineer is introduced.
Will you complete our security questionnaire?Yes. Send it with the enquiry. We answer it as written and mark anything we cannot meet rather than working around the question.

Data and access

Your data stays in your boundary.

The simplest way to protect client data is to avoid holding it. Our default operating model keeps production data inside the client estate and makes every action attributable to a named person.

Client data handling

The safest copy of your data is the one that never leaves your environment. Our default is to work inside your systems rather than take extracts.

  • No production data copied to local machines as a matter of course
  • Where sample data is genuinely needed, it is masked or synthetic
  • Any approved extract is held only for the agreed purpose and deleted after
  • Client material removed from our side at the end of an engagement, confirmed in writing

Access control

Access is granted per person, at the least level that lets the work happen, and it is yours to give and take away.

  • Named individual accounts, never shared logins
  • Multi-factor authentication on every account that supports it
  • Access requested in writing and reviewed when the team changes
  • Removal within one business day of a person leaving the engagement

Working in your systems

On most engagements we are users inside your estate, which keeps the audit trail in one place: yours.

  • Your repositories, your tracker, your cloud and platform tenants
  • Your review gates, branch rules and release approvals
  • Activity attributable to a named engineer in your own logs
  • Client-owned licences and accounts rather than ours

Building software

Controls that sit inside the engineering process.

Review, secrets handling and environment separation are part of how work is built, not a checklist applied before release.

Secure development

Security is handled where the code is written rather than inspected at the end of a project.

  • Peer review on every change, through your review process where you have one
  • Dependency updates raised as work, not left to drift
  • Input validation, output encoding and authorisation checked at review
  • Platform security models, including sharing and visibility, designed deliberately

Secrets management

Credentials belong in a managed store, not in a repository, a ticket or a chat message.

  • No credentials, keys or tokens committed to source control
  • Secrets held in the vault or secret manager your platform provides
  • Credentials issued per person and per environment
  • Rotation requested immediately if exposure is suspected

Environment separation

Development, test and production are kept apart, and production access is the exception rather than the working default.

  • Build and prove work in development or sandbox environments
  • Production access only where the role requires it, and only when granted
  • Release through your approval path, on your cadence
  • Test data kept out of production and production data out of test

People and devices

Who does the work, and on what.

Most supplier risk is people risk. Devices are controlled, confidentiality is contractual at both company and individual level, and the people on your engagement are our employees.

Device posture

Work happens on company-controlled machines from our Galle office, configured before an engineer is given client access.

  • Full disk encryption and screen lock enforced
  • Endpoint protection and current operating system patches
  • No removable media for client material
  • Personal devices are not used for client systems or client data

Confidentiality

Confidentiality is contractual for the company and for every individual, and it is signed before anyone sees your systems.

  • Your non-disclosure agreement signed at company level
  • Confidentiality and intellectual property terms in every employment contract
  • Intellectual property in delivered work assigned to you
  • No client named as a reference, and no work published, without written approval

Subcontracting

You are entitled to know who is doing the work. Our position is that it is us, and that anything else is a decision you make.

  • Delivery by people employed by Insteller
  • No undisclosed third parties and no offshoring of your work onward
  • Any proposed specialist named and approved in writing first
  • The same confidentiality terms flowed down if you approve one

When something goes wrong

Disclosure early, continuity by design.

Two commitments matter more than any control list: that you hear about a problem from us before you hear it elsewhere, and that an engagement does not depend on one person being available.

Incident response

If something goes wrong on our side, you hear it from us, early, with what we know and what we do not.

  • A single named contact for security matters on every engagement
  • Notification to you without delay once an issue is suspected, not once it is confirmed
  • Immediate containment, including credential rotation and access suspension
  • A written account of what happened, what was affected and what changed as a result
  • Your own incident process followed where you have one, in place of ours

Business continuity

A single delivery base is simpler to secure, so continuity is handled through redundancy in people, power and connectivity.

  • More than one engineer familiar with each live engagement
  • Documentation and access held by the company, not by an individual
  • Backup power and a secondary internet path at the Galle office
  • Ability to work from an alternate location on company machines
  • Handover notes maintained so an engagement survives a personnel change

Scope of this page

What this page is, and what it is not.

Being precise about the limits is part of being credible about the rest.

What it is

A description of the practices we run on client engagements today, maintained as those practices change.

  • Evidence available on request for any item listed
  • Completed against your questionnaire in your own format
  • Adjusted to your requirements where your terms are stricter than ours

What it is not

It is not a certification, an audit report or a contractual commitment on its own.

  • No ISO 27001, SOC 2 or equivalent certification is held or claimed
  • Contractual obligations come from the signed agreement, not this page
  • Requirements specific to your client are agreed in writing before work starts

Security questions can go to info@insteller.comor through the enquiry form. Each engagement has a single named contact for security matters.

Supplier assessment

Send us your security questionnaire.

Attach it to your enquiry and we will complete it in your format, including the items we cannot meet. It is faster than working out from a web page whether we clear your bar.