Trust center

Security & compliance.

Startups hand us positioning, roadmaps and unreleased products. This page states exactly how we protect them — and where we are honest about what we have not yet certified.

SOC 2 Type II readiness

We operate against a SOC 2 Type II readiness program: documented security policies, onboarding and offboarding checklists, quarterly access reviews, vendor risk review, and a written incident response runbook with defined client notification steps. We are not yet SOC 2 certified — no independent audit report has been issued, and we will say so plainly until one has been.

Encrypted client communication

Client collaboration happens in Slack, Notion and Google Workspace over TLS 1.3 in transit with provider-managed encryption at rest. Credentials are shared through a password manager with time-boxed access, never over email or chat. Devices used on client work require full-disk encryption, screen lock and MFA.

Least-privilege access

Team members receive the minimum access needed for their sprint scope. Access is requested per system, logged, reviewed quarterly, and revoked within one business day of a roster change or engagement end.

Strict NDA & IP protection

A mutual NDA is signed before any confidential detail is exchanged. Our master services agreement assigns 100% of work product, copy, designs, code, playbooks and campaign assets to you from day one. Accounts and domains are created in your ownership, not ours. We name you as a reference or publish a case study only with written approval.

Secure infrastructure

This site is served over HTTPS with TLS 1.3, HSTS and hardened response headers. Forms are validated on both client and server, rate limited, and protected by bot mitigation (Cloudflare Turnstile) plus a hidden spam trap field.

Subprocessors & retention

We use Google Workspace, Slack, Notion and HubSpot to run engagements. Client data is retained only for the engagement plus a 90-day wind-down window, then deleted on request. Ask us for the current subprocessor list before signing.

Report a vulnerability

Email security@redbeard.team with steps to reproduce. We acknowledge within two business days and will keep you updated until the issue is closed. Please avoid testing that degrades service or touches other people's data.

Security questionnaire or DPA needed for procurement? Write to hello@redbeard.team.