Security & Compliance
Last updated September 9, 2026. What we hold, what's in progress, and how we handle your code and data during an engagement.
Pre-cleared Business Associate Agreement (BAA) template, executed per engagement for healthcare clients.
Mutual NDA executed in under 24 hours; Data Processing Addendum available for any engagement handling regulated personal data.
Formal audit not yet complete. Ask your scoping engineer for current target timeline before relying on this for a compliance decision.
Certification not yet complete. Ask your scoping engineer for current status.
1. Data handling
During an engagement, we access only what a signed SOW scopes: source repositories, staging/production infrastructure needed to build and ship, and any business data explicitly required for the work. Access is credentialed per-engineer, not shared, and revoked at engagement end unless a support retainer is in place.
2. IP ownership and assignment
Unless the SOW states otherwise, work product you pay for is yours — code, architecture documents, and designs assign to you on payment. We don't retain a license to reuse your proprietary business logic in other engagements. Reusable internal tooling we bring to every engagement (not built specifically for you) remains ours.
3. Source code and repo handover
At handoff (see our delivery process), you receive full repository ownership, infrastructure access, and recorded architecture walkthroughs — not a document dump. If an engagement ends early, in-progress code in your repository is yours as of the last invoiced milestone.
4. Subprocessors
We use a small, vetted set of vendors to run our own business (site hosting/CDN, CRM, calendar booking, analytics) — none of which touch client source code or production credentials unless explicitly scoped into an engagement (e.g., a client's own cloud provider). A current subprocessor list is available on request.
5. Incident response
If we identify a security issue in something we built or maintain for you, we notify the named technical contact on the engagement as soon as it's confirmed — not after root-cause analysis is complete — and follow with a written summary once resolved.
6. Vendor risk / due diligence
For enterprise procurement and vendor-risk reviews, we can provide: engagement references, our current compliance status (above), our subprocessor list, and answers to a standard security questionnaire. Email hello@runwhatmatters.com with "vendor risk review" in the subject line.