Skip to content
Shaaztechnologies

Security & compliance

Your code and data, handled with care

We work with healthcare and retail clients whose data is sensitive and regulated. Security is built into how we engage, how we build and how we use AI.

01 / Practice

NDA-first engagement

Confidentiality starts before the first technical conversation.

  • Mutual NDA signed before discovery or code access
  • Business Associate Agreement signed before any PHI access (healthcare)
  • Data Processing Agreement available for UK and EU clients under GDPR
  • Named engineers only, with access reviewed at every change in the team

02 / Practice

Secure software development lifecycle

Security is part of how we design, build, review and ship.

  • Threat modelling for new features that touch sensitive data
  • Mandatory peer review on every change, including AI-assisted code
  • Automated dependency, secret and static analysis scanning in CI
  • OWASP Top 10 informed coding standards and security testing
  • Separate environments, with production changes via pipeline only

03 / Practice

Data handling

We keep sensitive data out of places it does not need to be.

  • Synthetic or de-identified data in development and test by default
  • Encryption in transit (TLS 1.2+) and at rest in every environment we build
  • Least-privilege access with MFA on all client systems and our own tools
  • Client data stays in the client's cloud accounts and regions
  • Secure deletion of data and credentials when an engagement ends

04 / Practice

Responsible use of AI tools

AI-native does not mean careless with your code or data.

  • Only enterprise AI tools that do not train on client code or data
  • AI tooling scoped per client, and disabled where policy requires
  • No PHI or personal data in AI prompts
  • Every AI-assisted change is reviewed and owned by a senior engineer

Our compliance position

HIPAA-aware and compliance-ready, stated plainly

Shaaz Technologies does not currently hold HIPAA, SOC 2 or ISO 27001 certifications or attestations. Our processes are HIPAA-aware and compliance-ready: we build and document systems so that your organization can meet its own regulatory obligations, and we are happy to complete security questionnaires and sign BAAs and DPAs.

Next step

Need a security questionnaire completed?

Book a call or send it over. We'll answer honestly and quickly, and walk your team through how we'd handle your data.

Book a call