Security
Security
How we protect your data, systems and trust — by default.
Our Approach to Security
Security isn't an afterthought at SpaceGrey — it's built into how we design, develop, and deploy every system we build, for our own operations and for our clients' projects.
Data Protection Practices
- Data encrypted in transit (TLS/SSL) and at rest where applicable
- Access to client data restricted to team members directly involved in the relevant project
- Regular review of third-party tools and vendors for security compliance
Infrastructure Security
- Hosting on reputable, security-audited cloud providers (AWS, Vercel, GCP)
- Environment separation between development, staging, and production systems
- Regular dependency and vulnerability scanning across codebases we maintain
Access Control
- Role-based access control on internal tools and client systems
- Multi-factor authentication enforced on critical accounts and admin panels
- Immediate access revocation upon team member offboarding or project completion
Secure Development Practices
- Code review process before every deployment
- Secrets and credentials managed via secure environment variables, never hardcoded
- Regular audits of authentication and authorization logic in client-facing applications
Incident Response
In the event of a security incident affecting client data, we commit to prompt investigation, containment, and transparent communication with affected parties within 72 hours of discovery.
Reporting a Vulnerability
If you discover a security vulnerability related to our website or systems, please report it responsibly to spacegreyyy522@gmail.com. We appreciate responsible disclosure and will respond promptly.
Contact Us
For security-related questions or concerns: spacegreyyy522@gmail.com

