Published security profile
- • Central security standards
- • External assurance automation
- • Supplier and data-protection governance
These items describe the intended or evidenced baseline relevant to this company. They do not imply that every technical control is implemented identically across every system. Repository- or service-specific controls are only treated as operating where the relevant implementation and evidence exist.
Evidence and assurance
Security claims are evidence-led. Automated assurance, dependency audits, secret-exposure checks, SBOM generation, linting, type checking, tests, SAST/CodeQL, build verification and deployment verification are not claimed for this company unless the relevant project actually implements them.
Planned certifications, independent testing and future controls remain described as planned until completed. Detailed evidence may contain sensitive architecture, supplier, account or vulnerability information and is shared only where appropriate for legitimate due diligence.