Trust
Security
Softbitrix treats security as part of delivery — not a brochure claim. Below is how we approach protecting systems, data, and this website.
Our posture
Security controls are scoped to the engagement. A marketing site, a multi-tenant SaaS product, and an internal ERP do not share identical threat models — we design controls against the actual risk, not a one-size checklist marketed as a guarantee.
Application and delivery practices
- Least-privilege access to code, cloud, and client environments
- Secrets kept out of source control; environment-based configuration
- Dependency awareness and patching for libraries we introduce
- Secure defaults for authentication, sessions, and role-based access where in scope
- Input validation, output encoding, and protection against common web flaws (OWASP-oriented)
- Review of high-risk changes before production release when the engagement includes it
Infrastructure and operations
- TLS for data in transit on services we configure
- Hardened hosting baselines, firewalls, and network segmentation where applicable
- Backups and restore awareness for systems we operate under contract
- Monitoring and alerting aligned to the stack we are responsible for
- Documented incident response steps for production incidents in our remit
People and access
- Access granted for the duration of need and revoked when engagement ends
- NDA / confidentiality expectations for client material
- No sharing of production credentials over insecure channels
This marketing website
- Static front end with a minimal serverless contact endpoint
- Form submissions delivered via configured email infrastructure (for example Resend)
- Standard host-level HTTPS and edge security on our deployment platform
- No advertising trackers; cookie use limited as described in the Cookie Policy
What we do not claim
Softbitrix does not claim SOC 2, ISO 27001, or similar certifications on this page unless a current certificate is published with evidence. Formal penetration testing or compliance audits are arranged when the contract requires an independent assessor.
Vulnerability disclosure
If you believe you have found a security issue on softbitrix.com or a system we operate, email info@softbitrix.com with enough detail to reproduce the issue. Please avoid public disclosure until we have had a reasonable chance to investigate and remediate.