# Security and Compliance

> How we handle your code, your data and your access, plus the certifications and attestations we can put in writing.

Source: https://www.koombea.com/company/security-and-compliance/

---

A regulated buyer will look for this page before they look at the work. Here is what we do, what we hold, and what we are willing to attest to.


## What we attest to

On completion of a build we provide a written attestation covering the agreed security checks and any known critical or high-severity findings identified within that scope. That is a specific, bounded claim, which is what makes it worth having.

We are careful about the wording. No engineering organization can honestly attest that software is free of unknown vulnerabilities, and any partner offering you that sentence is telling you something about their rigour.

- Written attestation on completion, covering known vulnerabilities
- IP assignment on full payment, automatic and in the contract
- Software design and development unit appraised at CMMI-DEV/3
- Compliance QA available for HIPAA, PCI DSS and WCAG
- A governance, risk and compliance service line, on its own pricing basis

## How we handle your access

- **Least privilege**: Access is scoped to the engagement and removed when it ends.
- **Credential hygiene**: Secrets managed in a vault, never in a repository or a ticket.
- **Reviewed changes**: No unreviewed change reaches your production environment.
- **Audit trail**: Who changed what, when, and against which approved item.
- **Environment separation**: Development and production kept genuinely separate, including data.
- **Data minimisation**: We ask for the least production data the work actually needs.

## Where the line is

We prepare, implement, remediate and accompany. We do not issue your certificate, and no development partner can. An ISO/IEC 27001 certificate comes from an accredited certification body, a SOC 2 report from a licensed CPA firm, a PCI DSS Report on Compliance from a Qualified Security Assessor. You appoint them.

The same boundary holds inside our own work. Someone who designs and runs your information security management system cannot then independently assess it. We say that up front, because the ambiguity is what creates the dispute later.

If you need to know what Koombea itself holds, ask and we will answer in writing, naming what we have and what we do not.


## Compliance work is priced separately

Governance, risk and compliance work never prices in story points, because the output is an assessment and an evidence trail rather than a feature. It prices four ways: a monthly retainer, a fixed fee per assessment, a scoped engagement for testing, or a phase price that follows the audit stages.

You might need us to answer a security questionnaire, run a penetration test, review your HIPAA readiness, prepare you for SOC 2 Type II, or hold a vCISO retainer. Each one is a defined engagement with a defined deliverable. Ask in the Priority Sync.



