Security

Security

How we protect your data, systems and trust — by default.

Our Approach to Security

Security isn't an afterthought at SpaceGrey — it's built into how we design, develop, and deploy every system we build, for our own operations and for our clients' projects.

Data Protection Practices

  • Data encrypted in transit (TLS/SSL) and at rest where applicable
  • Access to client data restricted to team members directly involved in the relevant project
  • Regular review of third-party tools and vendors for security compliance

Infrastructure Security

  • Hosting on reputable, security-audited cloud providers (AWS, Vercel, GCP)
  • Environment separation between development, staging, and production systems
  • Regular dependency and vulnerability scanning across codebases we maintain

Access Control

  • Role-based access control on internal tools and client systems
  • Multi-factor authentication enforced on critical accounts and admin panels
  • Immediate access revocation upon team member offboarding or project completion

Secure Development Practices

  • Code review process before every deployment
  • Secrets and credentials managed via secure environment variables, never hardcoded
  • Regular audits of authentication and authorization logic in client-facing applications

Incident Response

In the event of a security incident affecting client data, we commit to prompt investigation, containment, and transparent communication with affected parties within 72 hours of discovery.

Reporting a Vulnerability

If you discover a security vulnerability related to our website or systems, please report it responsibly to spacegreyyy522@gmail.com. We appreciate responsible disclosure and will respond promptly.

Contact Us

For security-related questions or concerns: spacegreyyy522@gmail.com