Security & IP Protection Your Code. Your Data. Provably Yours.
Working with an external engineering partner means trusting them with source code, credentials and sometimes customer data. Here is exactly how that trust is protected at Dexsof — in contracts, in infrastructure and in daily practice.
Structural protection, not promises.
The controls that matter are the ones that hold even if the relationship ends tomorrow: your code lives in your repositories, your infrastructure runs in your cloud accounts, our access is least-privilege and revocable by you at any time, and IP assignment is written into the contract from day one. Nothing about your product depends on trusting us indefinitely.
How client work is protected.
The standing practices on every engagement — not an enterprise add-on.
NDA before any material is shared; full IP assignment in the services agreement; invoicing in USD or EUR through clean contracting.
Repositories, cloud infrastructure, domains and third-party services live in accounts you own. We work inside them as removable collaborators.
Engineers get the minimum access the task needs, via named accounts with 2FA — no shared credentials, no standing production access by default.
TLS in transit, encryption at rest on managed services, secrets in environment stores — never in code or chat.
Every change lands through reviewed pull requests; infrastructure changes go through code. Who changed what, when, is always answerable.
We build technical safeguards aligned with SOC 2, GDPR and HIPAA expectations and document them for your compliance process — stated honestly as alignment, not certification. See the healthcare and fintech practices for sector specifics.
Need deeper assurance — security questionnaires, architecture reviews, penetration testing? That is our cybersecurity service.
Common questions.
Anything not covered here, ask us directly — we answer within 24 hours.
Who owns the intellectual property?
You do, in writing, from the first day of the engagement. Code, designs, documentation and infrastructure configuration are assigned to you in the services agreement - not on final payment, not on handover.
Do you sign NDAs?
Yes, as standard and before any sensitive material is shared. We are equally comfortable with your paper or ours.
Where does our data live?
In your cloud accounts, in regions you choose. We do not route client production data through Dexsof-owned infrastructure. Development uses anonymised or synthetic data wherever feasible.
Are you SOC 2 / ISO 27001 certified?
We practice alignment with those frameworks - least-privilege access, audit trails, encryption, reviewed changes - and document the technical controls for your auditors. We do not currently hold the certifications themselves and will not claim otherwise.
What happens to access when the engagement ends?
You revoke it - everything runs in your accounts, so offboarding is removing collaborators you control. We also run a joint offboarding checklist: access removal, secrets rotation, documentation handover.
Procurement asking questions? Send them our way.
We answer security questionnaires directly and can walk your technical or legal team through any of these controls on a call.
