Trust
Security & Data Protection
Written for the reviewer who has to sign off on us as a supplier. It describes what we actually do — not an aspirational posture.
Our stance on this page
Security pages tend to describe the programme a company wishes it had. This one describes what is actually in place today. Where a control is planned rather than operating, it says so.
Access control
- Least-privilege access to client systems, granted per engagement and revoked at its end
- Multi-factor authentication on all company accounts and code repositories
- Credentials managed in a password manager, never shared over chat or email
- Access reviewed when anyone joins, changes role, or leaves
Encryption
- TLS for all data in transit, including internal tooling
- Encryption at rest through the managed services and cloud providers we deploy on
- Secrets held in a dedicated secret manager, never committed to a repository
Secure development
- Mandatory pull request review — no direct commits to protected branches
- Automated dependency scanning, with a defined window for patching known vulnerabilities
- Static analysis and linting enforced in CI
- A threat model produced during the Architect phase of each engagement
- Security and accessibility testing as gates in the Assure phase
People
- Confidentiality obligations in every employment and contractor agreement
- IP assignment terms in place before anyone touches client code
- Background verification is planned but not yet in force. We will not claim it as an operating control until it is.
Sub-processors
We do not subcontract client work to third parties without written consent. Where we use infrastructure or tooling providers that process client data, they are disclosed in the Data Processing Agreement and can be listed on request.
Incident response
- A named incident owner for every engagement, reachable through the escalation matrix
- Containment first, then notification — we will not delay telling you while we investigate
- Notification to affected clients without undue delay, and to the Data Protection Board where the DPDP Act requires it
- A written post-incident review shared with the affected client
Certifications
Laxora does not currently hold ISO 27001, ISO 9001, SOC 2, or CMMI certification, and no such marks appear anywhere on this site. If your process requires one, raise it early and we will tell you honestly where we stand rather than let it surface late in procurement.
Reporting a vulnerability
If you find a security issue in this site or in something we built, please report it to connect@laxorasoftware.com rather than disclosing it publicly. We will acknowledge within two business days, keep you updated, and credit you if you would like us to.
Last updated: 21 August 2026 · Version 1.0
