Security policy
This policy sets security expectations for people, systems, and software operated by NorthCoast DevOps LLC (ncdLabs).
Scope
Applies to ncdLabs personnel, contractors acting for ncdLabs, production and staging systems we operate, source repositories we control, and customer environments only to the extent we are engaged to access them.
Principles
- Least privilege for human and machine access.
- Defense in depth: transport security, application controls, encryption of sensitive secrets at rest, monitoring.
- Separation of environments (for example production vs staging) and tenant isolation in multi-tenant products.
- Prefer verified webhook and API authenticity over trusting network location alone.
- Minimize retention of sensitive data; prefer opaque identifiers over full PII when practical.
Identity and access
- Administrative access to cloud accounts, source control, and production secrets is limited to authorized operators.
- Customer-facing products use authenticated sessions or OAuth; state-changing APIs apply CSRF or equivalent origin checks where cookie sessions are used.
- Secrets (API keys, OAuth client secrets, encryption keys) are stored in platform secret stores or equivalent, not in source control.
- Access is revoked when engagement ends or when credentials are rotated after suspected exposure.
Cryptography and secrets
- Public services are served over TLS.
- OAuth tokens, CRM credentials, and similar secrets stored by ncdLabs products are encrypted at rest with application-managed keys held as platform secrets.
- Secret material is excluded from support UIs, routine logs, and customer-visible exports.
Application and change control
- Product code is version-controlled. Changes intended for production go through review and automated checks where the pipeline exists.
- Deployments to production systems are intentional releases with health verification after publish.
- Third-party integrations (for example Zoom, Stripe, CRM APIs) are scoped to the permissions required for the feature.
Logging and monitoring
- Operational logs and error monitoring are used to detect outages and diagnose failures.
- Logs are configured to avoid recording passwords, tokens, OAuth codes, and unnecessary registrant or customer PII.
Customer responsibilities
Customers remain responsible for lawful use of third-party accounts they connect, for configuring product features appropriately, and for access control inside their own organizations.
Contact
Security questions and suspected security issues: security@ncdlabs.com. Service outages: help@ncdlabs.com.