Security overview
How Ryha Technologies handles access, code review, testing authorisation and your data during an engagement.
Updated 26 July 2026
A short, honest account of how we handle security. Ask us for anything not covered here.
Access#
- Individual accounts, never shared logins.
- Multi-factor authentication on every account that supports it.
- Least privilege: access is scoped to the task and removed when the engagement ends.
Code#
Our security division reviews every release before it ships. The review looks for the failures that actually happen: unvalidated input, queries built by string concatenation, secrets committed to a repository, and authorisation checked in the interface but not on the server.
Testing#
Penetration testing is always scoped and authorised in writing before it begins. Reports are written to be acted on: severity, reproduction steps and a specific recommended fix per finding — not a scanner dump.
Your data#
- We sign an NDA before any brief is discussed.
- Production data is not copied to development environments.
- We keep no production credentials after handover.
Where a specialist partner delivers part of an engagement — see how we deliver — the information they need is shared with them, and no more than that. They are bound by the same confidentiality terms we are. If you would rather a scope stayed entirely in-house, say so and we will tell you honestly whether we can do it that way.
Incidents#
If something goes wrong on a system we operate, you hear it from us with what happened, what we did, and what changes so it does not recur.
