Security & Trust
Security is how we engineer, not an afterthought
StephensCode builds and operates software and networking services for business customers. This page summarizes the controls we run and the standards our program is built around. We are glad to share detailed documentation with customers and prospects under NDA.
Standards and frameworks
SOC 2
Our security program is designed and operated to align with the SOC 2 Trust Services Criteria for security, availability, and confidentiality. Formal SOC 2 Type II attestation is on our roadmap.
ISO/IEC 27001
Our information security management system is built around the ISO/IEC 27001 control set. Certification is on our roadmap.
HIPAA
We apply administrative, physical, and technical safeguards aligned to the HIPAA Security Rule and can execute Business Associate Agreements for healthcare engagements.
We use one unified control set to satisfy all three, and maintain our policies and evidence as version-controlled records so they stay current with what we actually run.
What we do
Access control
Least-privilege access with unique, named identities and multi-factor authentication for administrative access. Access is reviewed on a recurring basis and revoked promptly on role change.
Encryption
Customer traffic is encrypted in transit with modern TLS. Data at rest is protected with industry-standard encryption on the systems that store it.
Network protection
Internet-facing services sit behind a web application firewall with rate limiting, abuse controls, and network segmentation between environments.
Monitoring & logging
Security-relevant events are logged and monitored, with automated alerting on anomalies and a defined escalation path.
Secure development
Changes follow a documented lifecycle with peer review, automated static analysis, dependency scanning, and secret scanning before code ships.
Backup & recovery
Production data is backed up automatically, and backups are restore-tested on a schedule so recovery is proven, not assumed.
Incident response
A documented incident response process, including breach-notification procedures, with a post-incident review after every event.
Vendor management
We maintain a current subprocessor list, review vendors for adequate safeguards, and execute BAAs with any vendor that would handle protected health information.
Data privacy
We collect only the data needed to provide our services, classify it by sensitivity, retain it only as long as necessary, and dispose of it securely. We do not sell customer data.
HIPAA & healthcare
StephensCode does not require access to protected health information to deliver its standard services. Where an engagement involves PHI, we execute a Business Associate Agreement and apply HIPAA Security Rule safeguards to the systems in scope.
Request our documentation
Security questionnaires, our controls summary, and framework mapping are available to customers and qualified prospects under NDA. We also welcome responsible-disclosure reports; please contact us before disclosing publicly so we can investigate and remediate.
Program status: SOC 2 and ISO 27001 readiness in progress; HIPAA-aligned safeguards operational; formal attestation and certification are on our roadmap.