Skip to content

Security

Practical security for products you will run

GujjuTicks builds custom apps, websites, and software with practical security defaults: HTTPS, careful access, sensible backups, and ownership you control — not buzzwords or certificates we have not contracted for.

This page describes how we work day to day. It is not a legal warranty or a compliance attestation.

Direct answer

We treat security as part of delivery: authentication and roles where needed, hardened hosting basics, least-privilege access during build, and a clear handoff of credentials and repos at launch. Higher compliance (HIPAA, PCI, SOC2) is scoped only when the project requires it.

HTTPS

Default for live sites

Roles

Auth when the product needs it

Handoff

You keep access & ownership

Scoped

Extra compliance when required

What we do by default

Transport & hosting basics

TLS/HTTPS for production sites, sensible environment separation, and hosting choices matched to the product — not a one-size vendor pitch.

Authentication & permissions

When the product needs accounts, we design login, roles, and permission boundaries as part of the build — not as an afterthought plugin.

Secrets & access during delivery

Project credentials and deploy access are limited to people who need them. We prefer shared vaults / password managers over chat paste.

Backups & recoverability

For apps we host or help host, we plan basic backup and restore paths appropriate to the stack. Exact RPO/RTO is agreed per project.

Dependencies & updates

We keep frameworks and packages on maintainable versions and discuss security updates as part of launch and optional ongoing support.

Ownership & exit

Repos, hosting panels, domains, and credentials are handed over per written terms. We design for handoff, not lock-in.

What we scope separately

Some industries need formal audits, penetration tests, or regulated handling of data. We can participate or coordinate — those are explicit line items, not assumed in every website or MVP.

  • Formal penetration testing by a third party
  • SOC 2 / ISO / HIPAA / PCI programs
  • Dedicated WAF, SIEM, or 24/7 SOC monitoring
  • Custom data residency or legal DPA language beyond standard project terms

For healthcare, fintech, and sensitive data

Tell us early what data you store and which rules apply. We will either design within a practical bar, recommend specialists, or decline work we cannot support honestly.

After launch

Security is ongoing. Optional maintenance retainers cover patching, monitoring basics, and small hardening tasks — see Ongoing support under Services.

Have compliance constraints?

Share them in your brief — we will say what we can own and what needs a specialist.