Security & Compliance
Last updated June 1, 2026
We take the security of client data and our own systems seriously, both in how we operate this website and in how we build software for clients.
Our approach
Security is considered from the start of every engagement, not bolted on at the end — from infrastructure design through to code review and deployment.
Infrastructure & hosting
This website is hosted on infrastructure with built-in DDoS protection, automatic TLS, and a global CDN. Client projects are typically deployed on major cloud providers (AWS, GCP, or Vercel) following each provider's security best practices.
Data encryption
Data is encrypted in transit (TLS) across all sites and applications we build. Encryption at rest is applied to sensitive data stores on client projects.
Access controls
Access to client systems and credentials is limited to engineers actively working on that engagement, and revoked promptly when an engagement ends or a team member departs.
Vulnerability disclosure
If you've found a security issue with this website, please email security@softhorizon.com with details. We aim to acknowledge reports within two business days.
Compliance
For client engagements with specific compliance requirements (data residency, sector-specific regulation, etc.), we scope those requirements during discovery and build to meet them.