Legal

Security

How we protect data and build security into everything we design, engineer, and operate.

Last updated: July 5, 2026

1. Our Approach to Security

Security is not a feature we add at the end — it is a discipline we build into every stage of design, engineering, and operations. This page describes the safeguards we apply to protect our own systems and the platforms we build for our clients.

2. Data Encryption

We protect data at rest and in transit using industry-standard encryption:

  • All traffic to and from our website is encrypted using TLS.
  • Sensitive data at rest is encrypted using strong, modern algorithms.
  • Secrets and credentials are stored in dedicated secret-management systems, never in source code.

3. Access Control

We operate on the principle of least privilege. Access to systems and data is granted only where required for a specific role, is reviewed regularly, and is protected by multi-factor authentication.

  • Role-based access with regular entitlement reviews.
  • Mandatory multi-factor authentication for internal systems.
  • Audit logging of access to sensitive systems and data.

4. Secure Development

Security is embedded in our engineering lifecycle rather than bolted on afterward:

  • Code review and automated testing on every change.
  • Dependency scanning and prompt patching of known vulnerabilities.
  • Secure-by-default architecture and infrastructure-as-code.

5. Infrastructure & Monitoring

We host on reputable cloud providers with strong physical and network security. We continuously monitor our infrastructure with logging, alerting, and observability so that anomalies are detected and addressed quickly.

6. Incident Response

We maintain an incident-response process to identify, contain, and remediate security events. Where an incident affects client data, we act promptly and communicate transparently in line with our obligations.

7. Compliance

We align our practices with recognized security and privacy standards, and we work with our clients to meet the regulatory requirements specific to their industry and jurisdiction. Our handling of personal data is described in our Privacy Policy.

8. Reporting a Vulnerability

We welcome responsible disclosure. If you believe you have found a security vulnerability in our website or services, please contact our security team so we can investigate and resolve it quickly. We ask that you give us a reasonable opportunity to address the issue before any public disclosure.

Questions about this document? Contact us at legal@nordhartongroup.com.

Turn complexity into your advantage

Tell us where you're headed. We'll help you get there faster — with fewer surprises and outcomes you can measure.