Skip to content
Security & Trust

Built to be trusted with enterprise data.

Our advisory engagements involve sensitive client data — strategic assessments, governance findings, transformation roadmaps, leadership briefings. Trust is the precondition. This page documents how we protect your information, what we depend on, and what we're working towards.

Security pillars

Six principles every System Pixels deployment is held to.

Encryption at rest and in transit

TLS 1.3 enforced everywhere. AES-256 at rest on D1 and R2. Field-level encryption for PII in our application database.

Edge-native infrastructure

Built on Cloudflare Workers, D1, R2 and KV. No origin servers, no VPNs, no perimeter to breach. Workloads execute in 300+ edge locations.

Least-privilege access

SSO with hardware-key MFA across our stack. Production secrets live in Wrangler secrets — never in source control, never in `.env` files.

Audit logs and observability

Every API call, secret access and admin action is logged with a per-request trace. Logs are retained 90 days and stream to a write-only sink.

Data residency on request

Default region is your nearest Cloudflare edge. For regulated workloads we can pin storage to EU, UK or India D1 replicas.

GDPR + DPDP aligned

Lawful basis recorded on every form submission. Right-to-erasure and data-portability requests honoured within 30 days. DPA template available on request.

Subprocessors

Every third-party that processes your data on our behalf is listed here. We notify customers 30 days before adding a new subprocessor.

VendorPurposeRegion
CloudflareHosting, edge compute, storage, CDN, WAF, bot protectionGlobal edge
ResendTransactional email deliveryUnited States
OpenAILLM inference for AI advisor demos (opt-in)United States
GoogleAnalytics (anonymised IP, aggregated only)United States

Compliance roadmap

We do not claim certifications we don't hold. Here is exactly where we are.

SOC 2 Type I

Targeting Q4

Drata or Vanta — controls scoped, evidence collection in motion.

ISO 27001

Planned

Following SOC 2 — gap analysis underway.

Penetration testing

Annual

Independent black-box engagement; summary available under NDA.

Bug bounty programme

Targeting Q4

Private programme via HackerOne or YesWeHack at launch.

Responsible disclosure

Found a vulnerability? Email info@systempixels.com with the subject line Security Disclosure. We acknowledge within 24 hours and patch critical issues within 7 days. Please don't access, modify, or download data that isn't yours.

Accepting new engagements now

Ready to begin your transformation advisory engagement?

One conversation with our advisory team is enough to identify the highest-value transformation opportunities for your organization — and define the path to realising them.

RM
PN
AS
DK
MJ

Trusted by 50+ organizations advised across 10+ verticals