Trust

Security and data protection

When you hire a development team, you hand over some of your most sensitive assets: your product idea, your source code, access to your servers and, often, your customers’ personal and financial data.

This page explains how RED SAG looks after those assets during a project, how we build security into the products we deliver, and how this website protects the information you send us. These are practices we follow, not certifications we hold; we say which is which.

In short

Our core commitments

  • We sign an NDA before seeing confidential material, on request
  • Intellectual property in custom work is assigned to you once paid for
  • Access to your systems is limited to the people who need it, and removed at the end
  • Credentials are shared through a password manager or vault, never in chat or email
  • Secrets are kept out of source code
  • Code can live in your own repositories from day one
Your data and code

How we handle client data and code

The everyday habits that decide whether a supplier is a security risk. They apply to every project, whatever its size.

NDA and confidentiality

On request, we sign your NDA or ours before any detailed discussion. Our project agreement also contains confidentiality terms covering everything you share with us during and after the project.

IP assignment

The agreement assigns the rights in the custom work we produce for you to you once the related invoices are paid. We do not reuse your business logic, designs or data in other clients’ projects.

Least-privilege access

We ask only for the access a task needs, prefer separate named accounts for each person over shared logins, and prefer staging or test environments over production. Where your systems support roles, we ask for the narrowest one.

Credentials in a password manager

Passwords, API keys and server credentials are exchanged and stored through a password manager or secrets vault, not pasted into WhatsApp, Slack or email. If you already use a vault, we use yours.

2-step login on our tools

We turn on two-step verification for the accounts we use to work on client projects, such as code hosting, cloud consoles, email and the password manager, wherever the service supports it.

Encrypted storage

Work laptops use full-disk encryption and screen locks. Client files are kept in access-controlled cloud storage rather than on personal devices or USB drives.

Your repositories, if you prefer

Code can be committed to a GitHub, GitLab or Bitbucket repository that you own from the first day, so you always hold the latest version and control who can see it.

Secrets never in code

API keys, database passwords and tokens are loaded from environment variables or a secrets manager. Configuration files with secrets are excluded from version control, and we rotate any key that is exposed by mistake.

Production data handled sparingly

We develop and test with sample or masked data wherever we can. When real personal or financial data is needed to fix a problem, we access the minimum necessary and do not copy it to local machines.

Backups

For systems we host or maintain, we set up automated backups stored separately from the main server and test that they can actually be restored, not just that they exist.

Offboarding at project end

When a project ends, or a person leaves the project, we hand back or revoke credentials, remove our accounts from your systems, and confirm in writing. We recommend you rotate any shared keys at handover, and we help you do it.

Confidentiality inside the team

Everyone who works on client projects is bound by confidentiality obligations. Only the people assigned to your project get access to its code and documents.

Secure by design

How we build secure products

Security that is designed in costs far less than security added after an incident or an audit finding.

Secure coding aligned with OWASP

We follow OWASP guidance, including the OWASP Top 10 and the Application Security Verification Standard (ASVS) as a checklist: input validation, parameterised queries, output encoding, safe file uploads and protection against common web attacks.

Code review

Changes go through review by a second developer before they are merged. Reviews look specifically at authentication, permissions, money calculations and anything that handles personal data.

Dependency updates

We use automated dependency alerts on the repositories we maintain and apply security updates to frameworks and libraries promptly, testing them before release.

Encryption in transit and at rest

HTTPS everywhere with modern TLS, encrypted databases and storage using the cloud provider’s encryption, and field-level encryption for especially sensitive values such as ID numbers or bank details where the design calls for it.

Role-based access

Admin panels and back offices are built with roles and permissions from the start, so a support agent, an accountant and an administrator each see only what they need.

Audit logs

Sensitive actions, such as changing a payout account, approving a loan, editing a balance or exporting customer data, are written to an append-only audit log with who, what and when.

Money-safe payment handling

Payment webhooks are verified by signature and processed idempotently, so a repeated notification can never credit an account twice. Balances come from a ledger, not a single editable number.

Penetration testing on request

For products that need it, we can arrange an independent penetration test by a third-party security firm of your choice or ours, and fix the findings before launch. The test is billed separately.

Regulation

Building for compliance

We are engineers, not lawyers or auditors. We build software that supports your compliance obligations, and we work alongside your compliance adviser, auditor or banking partner on anything that needs a formal opinion.

PCI DSS scope reduction

We integrate hosted payment pages, embedded checkout fields and tokenisation from licensed gateways such as Razorpay, Cashfree, PayU or Stripe, so raw card numbers never touch your servers. That keeps your PCI DSS scope as small as possible; your gateway and acquirer confirm which self-assessment applies.

RBI guidelines awareness

When building for Indian lenders, payment businesses and their partners, we design around the relevant RBI directions, such as digital lending, KYC, card tokenisation and payment data storage in India, and flag where your compliance team must confirm an interpretation.

DPDP Act 2023

For Indian products we design for India’s Digital Personal Data Protection Act: clear consent and notices, collecting only what is needed, deletion when the purpose ends, and support for user rights requests.

GDPR and UK GDPR

For clients in the UK and Europe we can act as a data processor under a data processing agreement, support international transfer mechanisms such as standard contractual clauses, and build privacy features such as data export and erasure.

Building a regulated product? Our fintech compliance guide explains which rules usually affect the software, and which licences and audits stay with you.

This website

How this website protects what you send us

  • HTTPS on every page, with HSTS so browsers never fall back to an unencrypted connection
  • Security headers, including a content security policy, nosniff, clickjacking protection, a strict referrer policy and a restrictive permissions policy
  • Forms are sent over HTTPS straight into our own CRM; the key that authorises them stays on our server and never reaches the browser
  • Files you attach to enquiries or job applications are stored privately in our CRM, not on a public server
  • Forms are protected against spam and automated abuse with hidden-field checks, timing checks and rate limits
  • A published security.txt file so researchers know how to report a problem

How we use the information itself is covered in our Privacy Policy.

Honesty

What we do not claim

RED SAG does not hold ISO 27001, SOC 2 or PCI DSS certification, and we do not display badges for them. Some suppliers do, and if your procurement policy requires a certified vendor, we will say so honestly rather than stretch the truth.

What we can do is complete your vendor security questionnaire, explain our practices in detail on a call, agree specific security controls in the contract, and build your product so that your own audits and certifications are easier to pass.

Responsible disclosure

Found a security problem?

If you believe you have found a vulnerability in this website or in software we operate, please tell us privately first so we can fix it before it is misused.

  • Email a description, the affected URL and steps to reproduce.
  • Do not access, change or delete other people's data, and stop once you have confirmed the issue.
  • Do not run denial-of-service, spam or social-engineering tests.
  • Give us reasonable time to fix the problem before sharing details publicly.

We acknowledge every good-faith report and keep you updated while we investigate. We do not currently run a paid bug bounty.

Security contact: info@red-sag.com

Machine-readable details: /.well-known/security.txt

FAQ

Security questions clients ask us

Are you ISO 27001, SOC 2 or PCI DSS certified?

No. We do not hold those certifications and do not claim to. This page describes the practices we follow. If your procurement process needs evidence, we can complete your security questionnaire, walk your team through our practices and agree specific controls in the contract.

Will you sign our NDA and data processing agreement?

Yes. We sign NDAs before detailed discussions on request, and for clients subject to GDPR or UK GDPR we can sign a data processing agreement that sets out how we handle personal data as your processor.

Who owns the code you write for us?

You do, once the related invoices are paid. The agreement assigns the intellectual property in the custom work to you, and at handover you receive the full source code, credentials and documentation. Code can live in your own repository from the start.

Can you work without access to our production data?

Usually, yes. We prefer to build and test with sample or masked data in a staging environment. If a problem can only be diagnosed with production access, we ask for the narrowest access for the shortest time and tell you when we are done.

Does using a payment gateway make my app PCI compliant?

Not automatically, but it can reduce the work a lot. Using the gateway’s hosted page or embedded fields means card data never touches your servers, which usually qualifies you for a much shorter self-assessment. Your gateway or acquirer tells you which assessment applies to you.

How do I report a security issue on your website?

Email info@red-sag.com with a description and steps to reproduce. Please do not access other people’s data, run destructive tests or disrupt the site. We will acknowledge your report and keep you updated while we investigate.

Have a security questionnaire for us?

Share a few lines about your idea. We reply within one working day with questions, a rough budget and the next step, with no obligation.

  • Reply within one working day
  • Fixed-price quote, no obligation
  • You own the code and the data
Google review
“Great service”
SanthiyaSee all 4 reviews on Google

Need a detailed estimate? Request a full quote