Skip to content

Security

We engineered to the FedRAMP Moderate standard before we had a customer

Security posture in a young software company usually arrives in a particular order. First the product, then the customers, then the enterprise buyer who sends a 300-question spreadsheet, then the engineer whose job for the next two quarters is to make the answers true. Cryptography gets swapped for a validated module. Logging gets extended to cover what the framework asks for. A supply-chain story is assembled from whatever the build pipeline happened to do.