When you hire a development team, you hand over some of your most sensitive assets: your product idea, your source code, access to your servers and, often, your customers’ personal and financial data.
This page explains how RED SAG looks after those assets during a project, how we build security into the products we deliver, and how this website protects the information you send us. These are practices we follow, not certifications we hold; we say which is which.
The everyday habits that decide whether a supplier is a security risk. They apply to every project, whatever its size.
On request, we sign your NDA or ours before any detailed discussion. Our project agreement also contains confidentiality terms covering everything you share with us during and after the project.
The agreement assigns the rights in the custom work we produce for you to you once the related invoices are paid. We do not reuse your business logic, designs or data in other clients’ projects.
We ask only for the access a task needs, prefer separate named accounts for each person over shared logins, and prefer staging or test environments over production. Where your systems support roles, we ask for the narrowest one.
Passwords, API keys and server credentials are exchanged and stored through a password manager or secrets vault, not pasted into WhatsApp, Slack or email. If you already use a vault, we use yours.
We turn on two-step verification for the accounts we use to work on client projects, such as code hosting, cloud consoles, email and the password manager, wherever the service supports it.
Work laptops use full-disk encryption and screen locks. Client files are kept in access-controlled cloud storage rather than on personal devices or USB drives.
Code can be committed to a GitHub, GitLab or Bitbucket repository that you own from the first day, so you always hold the latest version and control who can see it.
API keys, database passwords and tokens are loaded from environment variables or a secrets manager. Configuration files with secrets are excluded from version control, and we rotate any key that is exposed by mistake.
We develop and test with sample or masked data wherever we can. When real personal or financial data is needed to fix a problem, we access the minimum necessary and do not copy it to local machines.
For systems we host or maintain, we set up automated backups stored separately from the main server and test that they can actually be restored, not just that they exist.
When a project ends, or a person leaves the project, we hand back or revoke credentials, remove our accounts from your systems, and confirm in writing. We recommend you rotate any shared keys at handover, and we help you do it.
Everyone who works on client projects is bound by confidentiality obligations. Only the people assigned to your project get access to its code and documents.
Security that is designed in costs far less than security added after an incident or an audit finding.
We follow OWASP guidance, including the OWASP Top 10 and the Application Security Verification Standard (ASVS) as a checklist: input validation, parameterised queries, output encoding, safe file uploads and protection against common web attacks.
Changes go through review by a second developer before they are merged. Reviews look specifically at authentication, permissions, money calculations and anything that handles personal data.
We use automated dependency alerts on the repositories we maintain and apply security updates to frameworks and libraries promptly, testing them before release.
HTTPS everywhere with modern TLS, encrypted databases and storage using the cloud provider’s encryption, and field-level encryption for especially sensitive values such as ID numbers or bank details where the design calls for it.
Admin panels and back offices are built with roles and permissions from the start, so a support agent, an accountant and an administrator each see only what they need.
Sensitive actions, such as changing a payout account, approving a loan, editing a balance or exporting customer data, are written to an append-only audit log with who, what and when.
Payment webhooks are verified by signature and processed idempotently, so a repeated notification can never credit an account twice. Balances come from a ledger, not a single editable number.
For products that need it, we can arrange an independent penetration test by a third-party security firm of your choice or ours, and fix the findings before launch. The test is billed separately.
We are engineers, not lawyers or auditors. We build software that supports your compliance obligations, and we work alongside your compliance adviser, auditor or banking partner on anything that needs a formal opinion.
We integrate hosted payment pages, embedded checkout fields and tokenisation from licensed gateways such as Razorpay, Cashfree, PayU or Stripe, so raw card numbers never touch your servers. That keeps your PCI DSS scope as small as possible; your gateway and acquirer confirm which self-assessment applies.
When building for Indian lenders, payment businesses and their partners, we design around the relevant RBI directions, such as digital lending, KYC, card tokenisation and payment data storage in India, and flag where your compliance team must confirm an interpretation.
For Indian products we design for India’s Digital Personal Data Protection Act: clear consent and notices, collecting only what is needed, deletion when the purpose ends, and support for user rights requests.
For clients in the UK and Europe we can act as a data processor under a data processing agreement, support international transfer mechanisms such as standard contractual clauses, and build privacy features such as data export and erasure.
Building a regulated product? Our fintech compliance guide explains which rules usually affect the software, and which licences and audits stay with you.
How we use the information itself is covered in our Privacy Policy.
RED SAG does not hold ISO 27001, SOC 2 or PCI DSS certification, and we do not display badges for them. Some suppliers do, and if your procurement policy requires a certified vendor, we will say so honestly rather than stretch the truth.
What we can do is complete your vendor security questionnaire, explain our practices in detail on a call, agree specific security controls in the contract, and build your product so that your own audits and certifications are easier to pass.
If you believe you have found a vulnerability in this website or in software we operate, please tell us privately first so we can fix it before it is misused.
We acknowledge every good-faith report and keep you updated while we investigate. We do not currently run a paid bug bounty.
Security contact: info@red-sag.com
Machine-readable details: /.well-known/security.txt
No. We do not hold those certifications and do not claim to. This page describes the practices we follow. If your procurement process needs evidence, we can complete your security questionnaire, walk your team through our practices and agree specific controls in the contract.
Yes. We sign NDAs before detailed discussions on request, and for clients subject to GDPR or UK GDPR we can sign a data processing agreement that sets out how we handle personal data as your processor.
You do, once the related invoices are paid. The agreement assigns the intellectual property in the custom work to you, and at handover you receive the full source code, credentials and documentation. Code can live in your own repository from the start.
Usually, yes. We prefer to build and test with sample or masked data in a staging environment. If a problem can only be diagnosed with production access, we ask for the narrowest access for the shortest time and tell you when we are done.
Not automatically, but it can reduce the work a lot. Using the gateway’s hosted page or embedded fields means card data never touches your servers, which usually qualifies you for a much shorter self-assessment. Your gateway or acquirer tells you which assessment applies to you.
Email info@red-sag.com with a description and steps to reproduce. Please do not access other people’s data, run destructive tests or disrupt the site. We will acknowledge your report and keep you updated while we investigate.
RBI, NPCI, DPDP, PCI DSS, GDPR and more: what affects your software and what you must hold yourself.
NDA, discovery, proposal, sprints, QA, launch and handover, step by step.
Payments, lending, wallets and KYC systems built with audit-ready foundations.
Share a few lines about your idea. We reply within one working day with questions, a rough budget and the next step, with no obligation.
“Great service”
Need a detailed estimate? Request a full quote