Trust & Security
We hold ourselves to the same standard we hold our clients to. Our internal controls operate in alignment with ISO/IEC 27001 for information security and ISO 9001 for organizational discipline. Formal certification is planned; this page documents what we actually do today, not what a badge would imply.
Security controls without management discipline drift.
nesec is a small, engineering-led practice. We handle client systems, credentials, and sensitive context in the course of every engagement. The controls below are proportionate to a company of our size and risk profile, and they scale with us as we grow.
Two systems run in parallel. The management system (ISO 9001) keeps the organization credible. The information security system (ISO/IEC 27001) keeps the work credible. Neither stands alone.
ISO 9001 (alignment) — organizational & management
The spine that keeps the security side credible. Without management discipline, security controls drift.
-
01
Leadership
A named owner — the founder & principal engineer — is accountable for the management system, resourcing it, and reviewing it. Roles and responsibilities are written down, not tribal.
-
02
Planning
Annual and quarterly objectives are set, written, and reviewed. Operational planning is explicit: what we will deliver, by when, with what capacity.
-
03
Documents
Processes, policies, and decisions are kept as written records. Version control applies to code and to documents. No oral-only knowledge for anything that matters.
-
04
Competence
Every engineer keeps their skills current in their domain. Onboarding covers security responsibilities before any client system is touched.
-
05
Improvement
Nonconformities and near-misses are logged and addressed, not buried. The system is designed to get better, not to stay still.
ISO/IEC 27001 (alignment) — information security controls
Define the scope. Assess the risks. Select the controls. Operate them. Review them. Improve them.
-
01
Scope
The ISMS covers all nesec systems, devices, and information used to deliver engagements: engineering laptops, source control, secrets stores, communication channels, and client data we are entrusted with.
state: defined -
02
Risk assessment
A living risk register. Risks are identified, rated, and owned. New tools, vendors, and engagement types trigger a review before adoption, not after.
state: tracked -
03
Access control
Least-privilege by default. Access to client systems is granted per engagement, reviewed at handover, and revoked. Shared credentials are forbidden; individual accounts and short-lived tokens are the rule.
state: enforced -
04
Cryptography
Secrets are stored in a dedicated secrets manager. PGP is used for sensitive email where appropriate. End-to-end encryption is preferred for any data in transit.
state: encrypted -
05
Asset management
Information assets — code, documents, credentials, client data — are inventoried and classified. Handling rules follow the classification.
state: inventoried -
06
Secure operations
Devices are encrypted, patched on a fixed cadence, and remotely wipeable. Client data is not stored on local disks beyond what the engagement requires, and is returned or destroyed at handover.
state: hardened -
07
Supplier risk
Every external service we rely on is reviewed for security and data handling before adoption, and revisited periodically.
state: reviewed -
08
Incident response
A documented process covers detection, reporting, containment, eradication, recovery, and post-mortem. Incidents are reviewed openly; blame is not the goal, learning is.
state: drilled -
09
Business continuity
Critical functions have continuity plans. Backups are tested. We know what we would do if a key system or person were unavailable.
state: tested -
10
Compliance
We track the regulatory and contractual obligations that apply to us and to each engagement, and we map controls to them.
state: mapped
Both systems are reviewed on a regular cadence.
Findings, nonconformities, and improvement actions are tracked to closure. The point of the system is to make the next engagement safer and more effective than the last one, not to defend the status quo.
If you believe you have found a security issue in any nesec system or in a system we operate for a client, follow the instructions in our security.txt. We acknowledge responsible disclosure and respond within one business day.
Alignment today. Certification on the roadmap.
nesec operates in alignment with ISO/IEC 27001 and ISO 9001. We are not yet formally certified by an external auditor.
We chose to build the operating model first and pursue the certificate second. A badge without the underlying system is theater; the system without the badge is a claim. The system is built. Certification is planned.
For procurement: we are happy to walk you through the controls above, share the relevant policies on request, and discuss our certification timeline as part of any vendor risk assessment.
Request our policies.
The summaries above are intentionally non-exhaustive. For specific inquiries — due diligence questionnaires, procurement reviews, vendor risk assessments — and to request a copy of the relevant policies (information security policy, access control policy, incident response plan, risk treatment statement, business continuity plan), send an email to security@nesec.ai and we will get back to you within one business day.
security@nesec.ai →