// TRUST

SECURITY &
DATA PRACTICES

What we do with your code, your access and your clients' data when we work inside your team. Written for agencies whose own clients will ask.

Last Updated: September 26, 2026

Paperwork Before Access

  • A mutual NDA is signed before we see any code, credentials or client data.
  • Confidentiality, IP assignment and non-solicitation are written into the services agreement, not left to the NDA alone.
  • When the work involves personal data of your users or your clients' users, we sign a data processing agreement, including the transfer terms your jurisdiction requires.

Access Through Your Accounts Only

  • We work through accounts you issue: your Git host, your cloud, your Slack or Teams, your tracker. We don't ask you to share logins.
  • Each engineer gets their own named account. No shared credentials, so every action is traceable to a person.
  • We request the least access the work needs and ask before anything is widened, such as production or billing access.

Two-Factor Everywhere

  • 2FA is switched on for every account we use on your behalf, and on our own email, Git and password manager.
  • Secrets live in a password manager or your secrets store. Never in chat messages, tickets or email, and never committed to a repository.

Devices

  • Client code stays on company work machines with full-disk encryption and screen lock. Not on personal devices.
  • No client code or data is pasted into public AI tools. Where AI assistance is used on your code, we agree the tool and its data settings with you first.

Client Data

  • We work against staging or anonymised data wherever possible. Production personal data is accessed only when a task needs it, and only in place.
  • We don't copy production databases to local machines.
  • Nothing you share is used for any other client, portfolio or marketing without your written permission.

Offboarding Checklist

  • When an engineer rolls off, or the engagement ends, we send you a written list of every account and key they held so you can revoke it the same day.
  • Local copies of your code and data are deleted, and we confirm that in writing.
  • Handover notes and documentation are left in your repo or wiki, not in ours.

If Something Goes Wrong

  • If we suspect a leaked credential or any exposure of your data, we tell you within 24 hours, help rotate what's affected and write up what happened.

Security Questionnaires

If your client sends a vendor security questionnaire, send it to contact@thebeyondhorizon.com and we'll complete it. See also our privacy policy and how we work with agencies.

The Beyond Horizon is a trading name of QuantGPT Technologies Private Limited, Ajmer, Rajasthan, India.