SoftHorizon

Security & Compliance

Last updated June 1, 2026

We take the security of client data and our own systems seriously, both in how we operate this website and in how we build software for clients.

Our approach

Security is considered from the start of every engagement, not bolted on at the end — from infrastructure design through to code review and deployment.

Infrastructure & hosting

This website is hosted on infrastructure with built-in DDoS protection, automatic TLS, and a global CDN. Client projects are typically deployed on major cloud providers (AWS, GCP, or Vercel) following each provider's security best practices.

Data encryption

Data is encrypted in transit (TLS) across all sites and applications we build. Encryption at rest is applied to sensitive data stores on client projects.

Access controls

Access to client systems and credentials is limited to engineers actively working on that engagement, and revoked promptly when an engagement ends or a team member departs.

Vulnerability disclosure

If you've found a security issue with this website, please email security@softhorizon.com with details. We aim to acknowledge reports within two business days.

Compliance

For client engagements with specific compliance requirements (data residency, sector-specific regulation, etc.), we scope those requirements during discovery and build to meet them.