CIA Development, LLC is a small, owner-operated product studio. Our security model favors a deliberately small attack surface, modern defaults, and least-privilege access over complexity. We are not currently SOC 2 or ISO 27001 certified; the controls described here reflect what we actually do today. We're happy to complete security questionnaires and sign a mutual NDA — contact security@cia.dev.

Hosting & infrastructure

Encryption

Access control

Application & development security

Patching & vulnerability management

Monitoring & logging

Backups & resilience

Endpoint security

Incident response

If we identify a security incident, we investigate, contain, and remediate it as a priority. Where an incident affects data we process on a client's behalf, we commit to notifying the affected client without undue delay and within 72 hours of confirming the incident, along with the information needed to meet their own obligations.

Reporting a vulnerability

Found a security issue? Please see our Vulnerability Disclosure Policy or email security@cia.dev.