NYC Digital Agency
Trust & Security

Our security posture.

Last updated: August 12, 2026

Enterprise buyers ask about this before anything else. Here is exactly how we handle your data and code — no vague assurances.

1. Hosting & Infrastructure

Client applications we build are typically deployed on Vercel or your own cloud (AWS/GCP), with databases on managed providers (Neon, Supabase, or your existing infrastructure). We do not run our own unmanaged servers for client production workloads.

2. Data Handling

We access production data only when required for debugging or migration, with explicit client authorization. Credentials are stored in a password manager with per-project vaults, never in plaintext or shared documents.

3. Confidentiality & NDAs

We sign a mutual NDA before any discovery call that involves proprietary business data. Project-specific confidentiality terms are included in every Master Services Agreement.

4. Access Controls

Team access to client systems is scoped per project and revoked at engagement end. We use SSO and hardware-key 2FA internally across engineering tooling (GitHub, cloud consoles, password manager).

5. Compliance Roadmap

We are not currently SOC 2 certified. For clients that require it, we scope SOC 2 Type II readiness — policy documentation, access logging, and audit prep — as a defined workstream ahead of your compliance deadline, rather than claiming a certification we don't hold.

6. Incident Response

In the event of a security incident affecting a client system we manage, we notify the client within 24 hours of confirmation, alongside a written root-cause summary once the issue is resolved.

7. Report a Vulnerability

If you've found a security issue on this site or a NYC Digital Agency-built system, email security@nycdigital.agency. We aim to acknowledge reports within 48 hours.