How we think about it
We build systems that hold public-sector and commercial data, so security is part of the engineering rather than a review at the end. This page sets out what we do as standard and how to report a problem.
In the systems we build
Every platform we deliver starts from the same baseline:
- TLS everywhere, with HTTP redirected and modern ciphers only.
- Role-based access control enforced on the server, never only in the interface.
- Passwords hashed with a modern algorithm; secrets held in a managed secret store, never in source control.
- Parameterised queries and validated input at every boundary, to close off injection.
- Automated dependency scanning, with security patches applied as they land.
- Encrypted, tested backups — a backup nobody has restored is not a backup.
- Audit logging on privileged actions, retained for the period the engagement requires.
How we work
The same applies to how we run the studio:
- Multi-factor authentication on every account that supports it.
- Full-disk encryption on every machine that touches client work.
- Least-privilege access to client systems, granted for the engagement and revoked at handover.
- Client credentials held in a password manager, never in email or chat.
- Code review before anything reaches a production branch.
Hosting and data location
Most of what we deliver runs on AWS, in the region the engagement requires — for Indian public-sector work that generally means data stays in India. Everything ships containerised, so a system can equally be deployed to a state data centre or on-premise where your rules require it.
Reporting a vulnerability
If you have found a security issue in this site or in a system we built, we want to hear about it. Email studio@archilect.in with the subject line "Security" and enough detail to reproduce it. We will acknowledge within 72 hours, keep you updated while we investigate, and credit you when the fix ships if you would like us to.
Please give us a reasonable window to fix the issue before disclosing it publicly, and while testing, do not access data that is not yours, degrade the service for others, or run automated scans at volume. We will not pursue action against anyone who reports in good faith within those bounds.
What we do not claim
We are a three-person studio, not a certification body. We do not currently hold ISO 27001 or SOC 2, and we will say so plainly rather than imply otherwise. Where an engagement requires formal certification or a third-party audit, we support your review process and work with the assessors you appoint.
Questions about this page? Write to studio@archilect.in.