Trust

Security & Data Protection

How we protect client systems and data across discovery, build, launch and support. Written as practice, not aspiration.

Last updated August 2026

01Our security posture

We build systems that handle staff records, patient information and government education data. Security is treated as a delivery requirement with acceptance criteria, not a review at the end.

We are not currently certified to ISO 27001 or SOC 2. Where a client requires formal certification, we will say so plainly and work within their assurance framework rather than imply a standard we do not hold.

02Access control

  • Least-privilege access to client systems, granted per person and per environment.
  • Multi-factor authentication on all company accounts and code repositories.
  • Access reviewed at each milestone and revoked within 24 hours of a person leaving an engagement.
  • Production credentials held in a managed secrets store, never in source control or chat.

03Data handling

We prefer never to hold client production data. Where testing genuinely requires realistic data, we use anonymised or synthetic datasets by default.

  • Data residency and retention agreed in writing before any transfer.
  • Encryption in transit (TLS 1.2+) and at rest for data we control.
  • Client data is not used to train models or for any purpose beyond the engagement.
  • On completion, we delete client data from our environments and confirm deletion in writing on request.

04Secure development

  • Peer review on every change before it reaches a protected branch.
  • Dependency and secret scanning in the pipeline; known-vulnerable packages are blocked.
  • Parameterised queries, server-side authorisation checks and row-level security where the platform supports it.
  • Separate development, staging and production environments with separate credentials.
  • Input validation and output encoding applied at the boundary, with OWASP Top 10 risks reviewed before launch.

05Infrastructure and availability

We deploy to established cloud providers and managed platforms rather than self-managed servers, so patching, network isolation and physical security sit with providers that certify against them.

  • Automated backups with a tested restore procedure.
  • Monitoring and alerting on error rates, latency and uptime.
  • Infrastructure defined as code so environments can be rebuilt predictably.

06Incident response

If we become aware of a security incident affecting a client system, we notify the client without undue delay and in any case within 72 hours of confirmation, with what we know, what we are doing and what we need from them.

  • Contain, assess impact, notify, remediate, then write up root cause.
  • A written post-incident report is provided for any confirmed breach.
  • We support clients with their own regulatory notification obligations.

07People

  • Confidentiality obligations in every employment and contractor agreement.
  • Security and data-handling briefing on joining, refreshed annually.
  • Company-managed devices with disk encryption and screen lock.

08Reporting a vulnerability

If you believe you have found a security issue in this website or in a product we built, email neurobridgetechnologies@gmail.com with the words "Security Report" in the subject, along with steps to reproduce.

Please give us a reasonable window to investigate and remediate before disclosing publicly. We acknowledge reports within two working days, and we will not pursue action against good-faith researchers who avoid privacy violations, data destruction and service disruption.

Questions about this document? Email neurobridgetechnologies@gmail.com.

neurobridgetechnologies@gmail.com

Based in Lahore, PK

Serving clients globally

Registered ® with the Registrar of Firms

Services

Company

About UsWorking ModelPricingInternational ClientsContact Us

Legal & Trust

Privacy PolicyTerms & ConditionsCookie PolicyAcceptable UseSecurityIntellectual Property

© 2026 Neuro Bridge Technologies. All rights reserved.