Secure delivery defaults
Threat modeling for sensitive surfaces, dependency and secret scanning in CI, environment separation, and security review inside the sprint — not only at the end.
Security
Clients trust us with production systems and sensitive data. We design for that from the first sprint — and we publish how to report issues in Dathelyn-owned properties.
Threat modeling for sensitive surfaces, dependency and secret scanning in CI, environment separation, and security review inside the sprint — not only at the end.
Least-privilege access, short-lived credentials where practical, SSO when clients provide it, and audited administrative actions on production systems.
Encryption in transit, careful retention, need-to-know access to client data, and contractual terms matched to the sensitivity of the engagement.
Control mapping and evidence habits aligned with SOC 2, ISO 27001, and GDPR when your buyers require them — without pretending a checklist equals a certification.
Documented escalation paths, client notification commitments appropriate to the contract, and written follow-ups after material incidents.
Hosting, collaboration, and analytics vendors are reviewed for security and data-handling fit before they touch client or website operations.
If you discover a security issue in a Dathelyn-owned website or public property, email security@dathelyn.com with the subject “Security disclosure”. Include a clear description and steps to reproduce. Please allow us a reasonable time to investigate and remediate before public disclosure. We do not pursue legal action against good-faith, non-destructive research that follows these guidelines.
security@dathelyn.com →