Security & Enterprise

Engineers inside your boundary, under your controls

Senatio engineers work inside your repositories, your communication tools and your release process. That changes the security question: not what happens in a vendor’s environment, but what access you grant, what it is scoped to, who holds it, and how fast you can take it away.

Written for the person who signs off. Anything it does not cover, the security contact answers in writing.

Contracting, ownership and confidentiality

01

You own the IP. The customer owns the system and the IP under the engagement terms. No retained rights, no license-back.

02

Three agreements, not one. MSA, mutual NDA, and - where personal data is in scope - a DPA naming roles, retention and transfer mechanism. Your paper where you have it.

03

Confidentiality binds the individual. Engineers are bound through their employment, and it survives roll-off.

04

No onward subcontracting. Senatio personnel only, unless you consent in writing.

05

Your work is not our marketing. Nothing about a customer is published without permission. The case studies name no one.

06

Contracting entity. Zemuria Inc. in the USA, or Mercemur Technologies Pvt Ltd in India - settled in writing at the start.

Access control and least privilege

What is granted is the minimum, attributable to a named person, visible in your reviews, removable by you.

01

Customer-issued identity. Your accounts. No shared or intermediary logins between your systems and our engineers.

02

Least privilege by default. Access starts at the minimum and widens only when a specific task needs it.

03

Same process as your employees. Provisioning, approval, MFA, review and de-provisioning through your workflow. No contractor track.

04

Scoped to the engagement. No standing access to unrelated systems, repositories or projects.

05

In your access reviews. Named individuals in your directory, covered by your recertification.

06

Revocation never needs us. Access you issue, you withdraw - immediately, without our cooperation.

07

No standing production access. Granted deliberately under your approval process, only when the work requires it.

08

Joiners, movers, leavers. Moving between domains removes the old scope rather than accumulating a second one.

Code and repository access

Engineers commit under their own identity, through your review, subject to your branch protection and merge rules. No separate fork, no intermediary account, no path to production around your gates - the controls you already run apply automatically.

01

Secrets stay in your store. Your secret management, never credentials over chat - and nothing stored in Senatio systems.

02

Restricted arrangements are scoping. Read-only, excluded repositories, clean-room separation - decided at setup, not negotiated after access exists.

Customer environments and data handling

01

Work happens in your environment. Code, data and infrastructure stay where they already live.

02

Production data is not a debugging convenience. Synthetic or de-identified data wherever the task allows; real data only inside your controls.

03

No local copies as a matter of course. Where one is necessary: a managed, encrypted device, removed at offboarding.

04

Your tools, your retention. Your Slack or Teams, your Jira or Linear - the record sits inside your retention and legal hold by default.

05

Cross-border transfer, explicit. Engineers work from India. The DPA sets the mechanism at contracting, not during an audit.

People, devices and verification

In this model the personnel controls are the vendor controls: who the engineer is, what they work on, and the state of the machine they work from.

01

Background verification. At onboarding, with customer-mandated standards accommodated where an engagement requires them.

02

Managed, encrypted devices. Full-disk encryption, enforced lock, patched OS, endpoint protection, remote cut-off.

03

Named individuals, not anonymous capacity. A grant that maps to no specific person cannot be reviewed by anyone.

04

Security training. At onboarding and recurring, plus whatever your own program requires.

05

Structured offboarding. Senatio notifies you, removes local working copies, and confirms both.

Incidents and continuity

01

You hear it from us. Suspected compromise, credential exposure, lost device - escalated to your named contact without delay: what we know, what we do not, what we did.

02

Your incident process governs. Your severity definitions and procedure. Engineers support the investigation - they know the system.

03

Continuity is structural. Knowledge lives in documentation and shared ownership, so one person leaving does not remove your ability to operate.

04

Exit is planned, not improvised. You revoke, Senatio removes and confirms, and what was built stays yours - running, documented, owned.

Working inside regulated environments

Senatio engineers work with companies under SOC 2, HIPAA, ISO 27001 and GDPR. Your control environment governs the work, and the engagement is set up so including our engineers requires no exception to it - when your framework asks for evidence, your systems already hold it.

01

What this page does not claim. No certification - not SOC 2, not ISO 27001. Ask, and you get the current position in writing rather than a badge.

02

Questionnaires get completed. SIG Lite, CAIQ, VSAQ or your own, with a named person accountable. Where the answer is no, it says no and names the compensating control.

03

Regulated staffing constraints. Jurisdiction, residency or screening requirements are handled when the engagement is staffed.

Security contact

Vulnerability reports, engagement concerns and vendor-review documentation all land at one monitored address - and the answer comes in writing.

Vulnerability disclosure. Report privately and allow a reasonable window to investigate. Good faith is respected in return: no action against researchers who avoid privacy violations, service disruption, and data beyond what demonstrates the issue.

Security reports

security@senatio.com

NDAs, DPAs, vendor onboarding

contact@senatio.com

Disclosure record · RFC 9116

/.well-known/security.txt

On live engagements your existing Senatio contact works too - this address is simply the faster path.

Bring us a problem

Tell us what is actually happening

If there is technical work that needs an owner rather than an opinion, that is the conversation worth having.

Bring us a problemMissionsEmbedded FDEsTurnkey builds