Answers your security and legal teams ask for
This page is maintained by XentraSol to answer the questions that usually arrive as a spreadsheet. It describes our current practices as an engineering partner — it is not a certification or an independent audit.
NDA before discovery
Signed before any material changes hands, on your paper or ours.
IP yours from day one
Source code, cloud accounts, domains, and analytics are yours throughout — not on handover.
OWASP-aligned builds
SSO, role-based access, audit logging, secret management, and pen-test remediation as standard.
Data residency options
GCC, EU, UK, and US hosting regions, with the architecture to keep data where it must stay.
Named senior team
You see CVs and meet the engineers before signing. No bait-and-switch on staffing.
Response in one business day
Every enquiry answered by a person with a scope, a timeline, and a number.
Procurement detail
Where a requirement is client-specific, we confirm it in writing in the SOW rather than claiming it here.
Contracting
We work on MSA plus SOW, or your standard supplier agreement. Fixed-fee, retainer, and time-and-materials structures are all available.
Confidentiality
Mutual NDA signed before discovery. Client material is handled on need-to-know access and removed on request at the end of an engagement.
Intellectual property
All work product, source code, and deliverables are assigned to the client. You retain ownership of cloud accounts, repositories, and domains throughout.
Data protection
We process client data under a DPA where required, support GDPR data-subject request handling, and can restrict processing and hosting to a chosen region.
Security practice
Least-privilege access, managed secrets, dependency and vulnerability scanning in CI, code review on every change, and remediation of third-party pen-test findings.
Access & offboarding
Access is provisioned per engagement and revoked within one business day of an engineer rolling off. Credentials are never shared between clients.
Business continuity
Documentation, runbooks, and environment access are maintained continuously so any engagement can be transferred to your team without a knowledge gap.
References
Client references and detailed case-study documents are available on request during evaluation.
Shared responsibility
XentraSol is responsible for the security practices of our engineering team and for building your systems to the standards agreed in the SOW. You remain the owner and controller of your cloud accounts, production data, user access, and any third-party services connected to the platform.
Where a regulatory framework applies to your organisation, we build to the controls you specify and support your evidence gathering. We do not represent that an engagement in itself makes your organisation compliant with any standard. Report a suspected vulnerability in anything we have built for you to info@xentrasol.com and we will acknowledge within one business day.
Running a vendor review?
Send us your security questionnaire and contracting requirements. We'll return completed answers and our standard MSA, NDA, and DPA templates.