Security and data handling
What we do with your systems, your credentials, and your data during an engagement, written plainly enough to answer a vendor questionnaire.
Esspry LLC does not hold an ISO 27001 or SOC 2 certification, and we will not imply otherwise. We are a small studio, and the honest position is that our controls are practices rather than an audited management system.
This matters more than it sounds for the work we do. An engagement usually means we hold access to your domain, your hosting, your analytics, and your Google Business Profile. Those are the keys to your public presence, and the rules below are how we handle them.
What we will do is complete your vendor security questionnaire, sign your non-disclosure agreement and data processing agreement, and work inside whatever controls your organisation already operates. Where your policy requires something we do not currently do, we will tell you before the contract rather than after it.
How we work in practice
Access to your systems
- Named individual accounts, never a shared login, on every system we are given access to
- Multi-factor authentication enabled on every account that supports it
- The minimum role that allows the work, requested per system rather than blanket administrator access
- Access revoked at handover, and we will confirm revocation in writing when you ask
Credentials and secrets
- Secrets live in the hosting platform's encrypted environment store, never in the repository
- No secret is committed, and history is checked for accidental commits before handover
- Client-side bundles are reviewed so no server-side key is shipped to the browser
- Where credentials must be shared with us, they are shared through a password manager rather than email or chat
Production data
- We work against seeded or anonymised data by default
- Where live data is genuinely required, it is agreed in writing first and confined to the environment that needs it
- Copies taken for debugging are deleted when the issue is closed
- We do not move client data outside the systems you have approved
What goes into every build
- Separate development, preview, and production environments with separate credentials
- Security headers, transport security, and referrer policy configured at the framework level
- Authentication and session handling reviewed before launch, not after an incident
- Dependencies pinned, audited, and upgraded on a schedule rather than when something breaks
- Code review before merge, and a deployment history you can roll back
Subprocessors for this website
The services below process data submitted through this site. The subprocessor list for a client engagement is specific to that project and is confirmed in writing before work starts.
- Vercel
- Hosting and content delivery for this website
- GitHub
- Source control for this website
- Resend
- Delivery of enquiries submitted through the contact form
Reporting a vulnerability
If you have found a security issue in this website or in a system we operate, we want to hear about it. Write to security@esspryllc.com with the affected URL or endpoint, the steps to reproduce, and what you were able to access. Include a proof of concept if you have one.
We acknowledge reports within two business days and tell you what we intend to do about the finding. We will not pursue legal action against anyone who reports in good faith, stops at the point of demonstrating the issue, and does not access, alter, or retain data belonging to anyone else. We do not currently run a paid bounty programme, and we will credit you publicly if you want that.
Send us your security questionnaire
If your procurement process starts with a questionnaire and a set of agreements, send them with your enquiry and we will come back with them completed.