Security Posture & Engineering Controls
We scope and design client software around SOC 2, HIPAA, and ISO 27001 control frameworks. Northwind Studio is not currently SOC 2 or ISO 27001 certified; our internal engineering lifecycle follows verifiable controls: automated dependency auditing, branch protection, pre-commit secret scanning, and least-privilege access governance.
Documented Engineering Controls
We are documenting our internal controls; ask us for the current list. Our engineering processes are structured to enforce code reviews, branch protections, dependency vulnerability tracking, and least-privilege credential access across client engagements.
Vulnerability Disclosure & Responsible Reporting
We welcome security researchers who report potential vulnerabilities in our website or platform services responsibly. If you believe you have found a security vulnerability, please email our security team directly at security@northwindstudio.com. We review reports promptly and coordinate safe verification and remediation.
Need a security questionnaire review or custom BAA?
Our security leads can walk your security and procurement team through our technical safeguards and architecture.