09 · Security

How we hold your access.

What a firm of our size can honestly claim, and what it cannot. We would rather fail your vendor review on a clear answer than pass it on a vague one.

What we do not have

No ISO 27001, no SOC 2, no penetration test certificate. CALIPER LABS LLP is newly formed and claiming otherwise would be the first thing you find out was untrue. If your procurement requires a certification we do not hold, we will tell you at the first call rather than three weeks in.

What we do have is a small team, a short list of controls we actually follow, and a willingness to put an engineer on a call with your security people.

Access

Least privilege, and we ask for the narrowest access that lets the work happen. Multi-factor authentication on every account that touches client systems, with hardware keys or an authenticator app rather than SMS. Access is removed at handover as part of the handover, not as a task somebody remembers later.

We build in cloud accounts you own. That is a security decision before it is a commercial one: it means you can revoke us in a minute without asking, and nothing of yours lives anywhere we control.

Devices

Full-disk encryption, automatic screen lock and current operating systems on every machine used for client work. Client data does not go on personal devices or personal accounts. Nothing is kept on removable media.

Secrets

Credentials live in a password manager or the platform's own secret store, never in a repository, a ticket, a chat message or a spreadsheet. Where we set up a pipeline, secrets go in the platform's secret storage with the scope written down. We do not email credentials, and if you email them to us we will ask you to rotate them.

Production data

We prefer not to have it. Most of our work runs against synthetic or masked data, which is better engineering as well as less risk: a system designed against realistic synthetic data tends to survive real data better than one built against a convenient extract. Where production access is genuinely required it is scoped in writing, time-limited and logged.

In the code

Dependencies are pinned with a lockfile and updated deliberately rather than automatically. Every change goes through review before it reaches a main branch. Pipelines run checks on every pull request, and the checks are the kind that fail the build rather than print a warning nobody reads.

This website is the worked example. It ships a content security policy, HSTS, frame-ancestors none and nosniff, loads nothing from a third party, sets no cookies, and has a build check that fails if a third-party address ever appears in the output. You can verify all of that from your own browser without taking our word for it.

Reporting something

If you have found a vulnerability in anything we built or run, email [email protected] with enough detail to reproduce it. We will acknowledge within one business day and tell you what we are doing about it. We will not threaten you, and we will credit you if you want to be credited.

We do not run a paid bug bounty. We are too new for that to be honest.

Incidents

If an incident touches your data we tell you within twenty four hours of knowing, with what we know then rather than a complete account later. The data processing agreement sets out the obligations; this is the practice behind them.

Questions

Write to [email protected]. A person reads it.

Last updated 24 September 2026. All legal documents.