TRUST & SECURITY
Trust & Security
What we commit to on every engagement when it comes to your code, your data, and who can see either.
TRUST & SECURITY
What we commit to on every engagement when it comes to your code, your data, and who can see either.
BEFORE ANYTHING ELSE
Before we look at your codebase, your architecture, or anything specific about your business, we sign a mutual non-disclosure agreement. That's the starting point for every engagement, not an add-on you have to request — it protects your information and ours, and it means a conversation with us doesn't commit you to anything beyond keeping the details confidential.
ACCESS
Access to your code, credentials, and environments is limited to the engineers actually assigned to your engagement — not the whole team, and never shared or generic logins. When an engagement ends or someone rotates off it, their access is removed. We work inside the access boundaries you set: if you want us operating entirely inside your own cloud accounts and repos rather than ours, that's the default we're comfortable with, not a special request.
OWNERSHIP
Code, infrastructure configuration, and any other deliverables we produce for you belong to you, under the terms set out in your engagement agreement. We don't reuse your proprietary code on other projects, and we don't retain a copy for ourselves once an engagement wraps unless you've asked us to keep supporting it.
HOW WE BUILD
Code review before anything merges, separated development/staging/production environments, and version control on everything — these aren't practices we switch on for security-sensitive clients, they're how every engagement runs. Where a project touches particularly sensitive data or systems, we scope additional controls (audit logging, stricter environment isolation, data residency constraints) into the engagement itself rather than assuming a one-size-fits-all setup covers it.
WHERE WE STAND TODAY
Hashtha.ai is a small, early-stage team. We follow the practices on this page on every engagement, but we don't currently hold formal third-party security certifications like SOC 2 or ISO 27001 — pursuing those is on our roadmap as we grow, not something we'd claim before it's actually true. If a specific certification or compliance framework is a hard requirement for your project, tell us early and we'll give you a straight answer about whether we're the right fit right now.
SPECIFIC REQUIREMENTS
Data residency, a particular compliance framework, a security questionnaire your team needs filled out — these are easier to get right in a direct conversation than a general page can cover. Reach out via the Contact page and we'll work through it with you before anything starts. For how we handle data on this website itself — as opposed to inside a client engagement — see our Privacy Notice.