Skip to main content

Security & Trust

Security is how we engineer, not an afterthought

StephensCode builds and operates software and networking services for business customers. This page summarizes the controls we run and the standards our program is built around. We are glad to share detailed documentation with customers and prospects under NDA.

Standards and frameworks

SOC 2

Our security program is designed and operated to align with the SOC 2 Trust Services Criteria for security, availability, and confidentiality. Formal SOC 2 Type II attestation is on our roadmap.

ISO/IEC 27001

Our information security management system is built around the ISO/IEC 27001 control set. Certification is on our roadmap.

HIPAA

We apply administrative, physical, and technical safeguards aligned to the HIPAA Security Rule and can execute Business Associate Agreements for healthcare engagements.

We use one unified control set to satisfy all three, and maintain our policies and evidence as version-controlled records so they stay current with what we actually run.

What we do

Access control

Least-privilege access with unique, named identities and multi-factor authentication for administrative access. Access is reviewed on a recurring basis and revoked promptly on role change.

Encryption

Customer traffic is encrypted in transit with modern TLS. Data at rest is protected with industry-standard encryption on the systems that store it.

Network protection

Internet-facing services sit behind a web application firewall with rate limiting, abuse controls, and network segmentation between environments.

Monitoring & logging

Security-relevant events are logged and monitored, with automated alerting on anomalies and a defined escalation path.

Secure development

Changes follow a documented lifecycle with peer review, automated static analysis, dependency scanning, and secret scanning before code ships.

Backup & recovery

Production data is backed up automatically, and backups are restore-tested on a schedule so recovery is proven, not assumed.

Incident response

A documented incident response process, including breach-notification procedures, with a post-incident review after every event.

Vendor management

We maintain a current subprocessor list, review vendors for adequate safeguards, and execute BAAs with any vendor that would handle protected health information.

Data privacy

We collect only the data needed to provide our services, classify it by sensitivity, retain it only as long as necessary, and dispose of it securely. We do not sell customer data.

HIPAA & healthcare

StephensCode does not require access to protected health information to deliver its standard services. Where an engagement involves PHI, we execute a Business Associate Agreement and apply HIPAA Security Rule safeguards to the systems in scope.

Request our documentation

Security questionnaires, our controls summary, and framework mapping are available to customers and qualified prospects under NDA. We also welcome responsible-disclosure reports; please contact us before disclosing publicly so we can investigate and remediate.

Program status: SOC 2 and ISO 27001 readiness in progress; HIPAA-aligned safeguards operational; formal attestation and certification are on our roadmap.