Built to be trusted with enterprise data.
Our advisory engagements involve sensitive client data — strategic assessments, governance findings, transformation roadmaps, leadership briefings. Trust is the precondition. This page documents how we protect your information, what we depend on, and what we're working towards.
Security pillars
Six principles every System Pixels deployment is held to.
Encryption at rest and in transit
TLS 1.3 enforced everywhere. AES-256 at rest on D1 and R2. Field-level encryption for PII in our application database.
Edge-native infrastructure
Built on Cloudflare Workers, D1, R2 and KV. No origin servers, no VPNs, no perimeter to breach. Workloads execute in 300+ edge locations.
Least-privilege access
SSO with hardware-key MFA across our stack. Production secrets live in Wrangler secrets — never in source control, never in `.env` files.
Audit logs and observability
Every API call, secret access and admin action is logged with a per-request trace. Logs are retained 90 days and stream to a write-only sink.
Data residency on request
Default region is your nearest Cloudflare edge. For regulated workloads we can pin storage to EU, UK or India D1 replicas.
GDPR + DPDP aligned
Lawful basis recorded on every form submission. Right-to-erasure and data-portability requests honoured within 30 days. DPA template available on request.
Subprocessors
Every third-party that processes your data on our behalf is listed here. We notify customers 30 days before adding a new subprocessor.
| Vendor | Purpose | Region |
|---|---|---|
| Cloudflare | Hosting, edge compute, storage, CDN, WAF, bot protection | Global edge |
| Resend | Transactional email delivery | United States |
| OpenAI | LLM inference for AI advisor demos (opt-in) | United States |
| Analytics (anonymised IP, aggregated only) | United States |
Compliance roadmap
We do not claim certifications we don't hold. Here is exactly where we are.
SOC 2 Type I
Targeting Q4Drata or Vanta — controls scoped, evidence collection in motion.
ISO 27001
PlannedFollowing SOC 2 — gap analysis underway.
Penetration testing
AnnualIndependent black-box engagement; summary available under NDA.
Bug bounty programme
Targeting Q4Private programme via HackerOne or YesWeHack at launch.
Responsible disclosure
Found a vulnerability? Email info@systempixels.com with the subject line Security Disclosure. We acknowledge within 24 hours and patch critical issues within 7 days. Please don't access, modify, or download data that isn't yours.
Ready to begin your transformation advisory engagement?
One conversation with our advisory team is enough to identify the highest-value transformation opportunities for your organization — and define the path to realising them.
Trusted by 50+ organizations advised across 10+ verticals