Data handling
How we handle client code and data
- Least-privilege access: we request only the access each task needs.
- Access removed at the end of every engagement.
- Encrypted storage and transfer of client code and data.
- No client data on personal devices.
Methodology
How we test
Every security review follows the same steps, so you know what will happen and nothing is tested without your agreement.
Agree the scope
Which systems, environments and AI features are in scope, what's out of scope, and what a good outcome looks like.
Written authorization
Nothing is tested until you've authorized it in writing, including test windows and any limits on production testing.
Least-privilege access
Read-only access and dedicated test accounts wherever possible, set up for the engagement and removed when it ends.
Structured review
Code, configuration, data access and AI features are reviewed against a structured checklist, plus manual testing of your business logic.
Severity-rated report
Every finding is rated by severity, with evidence and a clear fix, and walked through with your team on a call.
Retest
Once fixes are in, we retest the findings and confirm in writing which are resolved.
AI use
Our AI-use policy
- Client code and data are never used to train models.
- No client data in consumer AI tools.
- Clients can restrict AI use on their engagement, per contract.
Contracts
Contracts we work under
NDA
Yours or ours, before any technical discussion.
DPA
Data processing agreement under GDPR Art. 28.
MSA + SOW
A master agreement, with a statement of work per engagement.
IP ownership
Deliverables belong to the client, per contract.
Subprocessors
Subprocessors
Providers that may process personal data on our behalf, for this website and our services.
Our current subprocessor list is available on request from contact@geektech.com.
Due diligence
Security questionnaires
We complete client security questionnaires on request, as part of your vendor onboarding.