Security Policy

Clients trust us with their code, stores and customer data. This page describes the general practices we follow to keep them safe.

Confidentiality and NDA

We sign a non-disclosure agreement before we receive project details. Client code and data are used only for the agreed work and are never shown in our portfolio without permission.

Access control

Each team member gets access only to the projects and systems they work on. Access is personal, never shared, and is removed when the work ends or a person leaves the project.

  • Least privilege: the lowest access level needed for the task
  • Personal accounts, no shared logins
  • Two-factor authentication (2FA) on code repositories, hosting panels and admin accounts where the service supports it
  • Access review at the end of each project

Code and staging

All code is stored in private Git repositories. Changes are built and tested on a staging site before they reach the live site, so clients see every change first and production is not used for experiments.

We use anonymized or test data on staging where possible.

Backups

Before updates, migrations and releases we make a backup of files and database. For clients on a support plan, we check that regular backups run and can be restored.

Passwords and secrets

Passwords, API keys and other secrets are kept in a password manager, not in email, chat or code. We ask clients to share credentials through secure channels and to change them after the project if they wish.

Responsible disclosure

If you find a security issue on artilab.pro or in a project we built, please write to info@artilab.pro with a description and steps to reproduce it. We will confirm receipt, investigate and keep you informed. Please do not share the issue publicly until it is fixed.