Security and compliance

What we will put in writing.

A regulated buyer will look for this page before they look at the work. Here is what we do, what we hold, and what we are willing to attest to.

What we attest to

On completion of a build we provide a written attestation covering the agreed security checks and any known critical or high-severity findings identified within that scope. That is a specific, bounded claim, which is what makes it worth having.

We are careful about the wording. No engineering organization can honestly attest that software is free of unknown vulnerabilities, and any partner offering you that sentence is telling you something about their rigour.

  • Written attestation on completion, covering known vulnerabilities
  • IP assignment on full payment, automatic and in the contract
  • Software design and development unit appraised at CMMI-DEV/3
  • Compliance QA available for HIPAA, PCI DSS and WCAG
  • A governance, risk and compliance service line, on its own pricing basis

How we handle your access

Least privilege

Access is scoped to the engagement and removed when it ends.

Credential hygiene

Secrets managed in a vault, never in a repository or a ticket.

Reviewed changes

No unreviewed change reaches your production environment.

Audit trail

Who changed what, when, and against which approved item.

Environment separation

Development and production kept genuinely separate, including data.

Data minimisation

We ask for the least production data the work actually needs.

Where the line is

We prepare, implement, remediate and accompany. We do not issue your certificate, and no development partner can. An ISO/IEC 27001 certificate comes from an accredited certification body, a SOC 2 report from a licensed CPA firm, a PCI DSS Report on Compliance from a Qualified Security Assessor. You appoint them.

The same boundary holds inside our own work. Someone who designs and runs your information security management system cannot then independently assess it. We say that up front, because the ambiguity is what creates the dispute later.

If you need to know what Koombea itself holds, ask and we will answer in writing, naming what we have and what we do not.

Compliance work is priced separately

Governance, risk and compliance work never prices in story points, because the output is an assessment and an evidence trail rather than a feature. It prices four ways: a monthly retainer, a fixed fee per assessment, a scoped engagement for testing, or a phase price that follows the audit stages.

You might need us to answer a security questionnaire, run a penetration test, review your HIPAA readiness, prepare you for SOC 2 Type II, or hold a vCISO retainer. Each one is a defined engagement with a defined deliverable. Ask in the Priority Sync.

Bring us the backlog.

In 30 minutes, we will show you what a Pod would ship first and how we would price it.