DotLinker Technologies logo
    Trust & Safety

    Security & Compliance

    How we think about security — in the software we build for clients, and on our own systems.

    Secure Development Lifecycle

    Security isn't a separate step bolted on at the end — it's part of how we work through discovery, design, development, QA, and launch on every engagement. Our QA & Testing phase specifically covers functionality, performance, and security before anything ships.

    Authentication

    We implement modern authentication patterns — including OAuth, JWT-based sessions, and multi-factor authentication where appropriate — tailored to each project's risk profile and user base.

    Encryption

    Data is encrypted in transit via TLS/HTTPS by default. Where a project handles sensitive data, we design encryption at rest into the architecture as well, not as an afterthought.

    Data Protection

    We follow data-minimization principles — collecting only what a system actually needs — and scope access to sensitive data by role. See our Privacy Policy for how we handle data on this website specifically.

    Backup & Disaster Recovery

    For production systems we build and manage, we set up automated backups and a recovery plan appropriate to the system's criticality and your recovery-time requirements.

    Monitoring & Logging

    We set up monitoring, logging, and alerting so issues are caught early rather than discovered by users — this is a standard part of our DevOps & Cloud engagements.

    Vulnerability Testing

    Code review and dependency vulnerability scanning are part of our QA process. For higher-risk projects, we scope additional security testing based on your specific requirements.

    Access Control

    We implement role-based access control and the principle of least privilege, so users and systems only have the access they actually need to do their job.

    Cloud Security

    For projects on Azure or GCP, we follow cloud provider security best practices — least-privilege IAM policies, network segmentation, and secrets management — as part of our DevOps & Cloud work.

    GDPR Considerations

    For products serving users in the EU or UK, we help incorporate GDPR-relevant practices — data minimization, clear consent flows, and support for data access and deletion requests — into the product itself. This is a design consideration we bring to relevant projects, not a certification DotLinker holds.

    Industry-Specific Compliance

    Different industries carry different requirements — healthcare projects need HIPAA-relevant data handling, fintech projects need stronger auditability and fraud controls. We factor these into the architecture for relevant projects. Where a client needs a specific certification or third-party audit (SOC 2, ISO 27001, PCI-DSS, etc.), that's scoped as part of the engagement rather than assumed upfront.

    A note on certifications

    Everything above describes how we approach security and compliance in practice. DotLinker does not currently hold formal certifications such as SOC 2, ISO 27001, or PCI-DSS — we won't claim them until we do. If your project requires a specific certification or compliance audit, tell us during discovery and we'll scope it honestly as part of the engagement.