Rydeum Start a project →
Security & Confidentiality

You're handing us your source code.

That is not a small thing to ask, so here is exactly how we handle it. In plain English, not legalese.

NDA on request, before you send anything Least-privilege access Deleted on request You own every account and line
What we commit to

Six things we promise in writing.

Not aspirations. If we cannot do it, we will not claim it.

01

NDA before anything moves

Ask and we sign a mutual NDA before you send a single file. If you have your own paper, we will sign yours. This is standard, not a favor.

02

Least-privilege access

Only the engineers actually assigned to your work get access, and only to what the work requires. No company-wide repository browsing, no "everyone can see everything."

03

You keep the keys

Every cloud account, repository, and domain stays in your name. We work inside your accounts, or in an isolated environment we hand over. We never hold your product hostage.

04

We work on a copy

For reviews and fixes, we work on a branch or a copy, never directly against your live site. Nothing ships to production without your explicit approval.

05

Deleted when you ask

When the engagement ends, we remove our copies of your code and revoke our access. Ask for confirmation and we will confirm it in writing.

06

Secrets are handled as secrets

We do not want your production credentials, and we will tell you when you are about to send them. If we find exposed keys in your code, rotating them is the first thing we tell you to do.

How you share it

You choose how much to hand over.

For a scan or a review, you do not have to give us your production infrastructure. You usually do not have to give us anything permanent at all.

A zip file

The lowest-trust option, and it works fine for a scan or a review. Export your code, send the archive, and we never touch a live system.

A read-only repo invite

Most common. Invite the assigned engineer as a read-only collaborator on a private repository, and revoke it whenever you like.

Scoped account access

Only for deployment and managed work, and only to the specific accounts required. You grant it, you see it, and you can pull it at any moment.

Honest limits

What we are not claiming.

We are not SOC 2 certified and we are not going to pretend otherwise. We are a senior engineering firm, not a compliance platform. What we offer is a signed NDA, least-privilege access, work on copies rather than your live systems, deletion on request, and a named senior engineer who is accountable for all of it. If your procurement process requires a formal certification we do not hold, tell us early and we will say so plainly rather than waste your time.

FAQ

The questions people actually ask.

Yes, and before you send anything. Email app-support@rydeum.com and ask. If you have your own NDA, send it and we will sign yours rather than argue about paper.

No. A zip file or a read-only repository invite is enough for a scan or a review. Production access only comes up for deployment or managed work, and even then it is scoped to what the job requires.

The senior engineer assigned to your work, and anyone you explicitly approve. Not the whole firm. You can ask who it is by name before you send anything.

No. Your code is used to do your work and nothing else. It is not used to train anything, and it is not shared with anyone outside the engagement.

We delete our copies and revoke our access. Ask for written confirmation and you will get it. Everything that matters was in your accounts the whole time anyway.

No, and we will not imply otherwise. We can help you get your product through a buyer's security review, and we do SOC 2 groundwork as part of managed infrastructure. But Rydeum itself does not hold that certification today.

Get started

Ask for the NDA before you send a thing.

Say the word and we will have it signed before you share a single file. A senior engineer reads every message.

NDA on request · Least-privilege access · Deleted when you ask · You own every account and line