Security overview

How Ryha Technologies handles access, code review, testing authorisation and your data during an engagement.

Updated 26 July 2026

A short, honest account of how we handle security. Ask us for anything not covered here.

Access#

  • Individual accounts, never shared logins.
  • Multi-factor authentication on every account that supports it.
  • Least privilege: access is scoped to the task and removed when the engagement ends.

Code#

Our security division reviews every release before it ships. The review looks for the failures that actually happen: unvalidated input, queries built by string concatenation, secrets committed to a repository, and authorisation checked in the interface but not on the server.

Testing#

Penetration testing is always scoped and authorised in writing before it begins. Reports are written to be acted on: severity, reproduction steps and a specific recommended fix per finding — not a scanner dump.

Your data#

  • We sign an NDA before any brief is discussed.
  • Production data is not copied to development environments.
  • We keep no production credentials after handover.

Where a specialist partner delivers part of an engagement — see how we deliver — the information they need is shared with them, and no more than that. They are bound by the same confidentiality terms we are. If you would rather a scope stayed entirely in-house, say so and we will tell you honestly whether we can do it that way.

Incidents#

If something goes wrong on a system we operate, you hear it from us with what happened, what we did, and what changes so it does not recur.