FxBytes

Security & ownership

Ownership means nothing if you can't leave.

Every commitment on this page exists so that ending an engagement with FxBytes costs you nothing but our contribution. That constraint makes the engineering better.

When the engagement ends

You keep everything that matters

You can leave

Stays with you

  • Code · Your repos

    Org repos · from commit one

  • Infrastructure · Your accounts

    Your cloud · your billing

  • IP · Assigned to you

    Not licensed back

What leaves

FxBytes access

Contractor seats · vault grants

AccessRevoked

Cost to you: our contribution only

Lock-in

None by design

Vendor trappedFree to leave
Code
Your repos
Infrastructure
Your accounts
IP
Assigned to you
Lock-in
None by design

Ownership

Four commitments we put in writing

  1. 01

    Your repositories from commit one

    Source control lives in your organisation. We work inside it under access we can lose without you losing anything.

  2. 02

    Your cloud, your data residency

    Infrastructure is provisioned in your accounts, under your compliance regime and your billing.

  3. 03

    IP assigned, not licensed

    Contracts assign all deliverable IP to you, including build tooling and infrastructure code.

  4. 04

    Exit designed in advance

    Mainstream stacks, documented decisions and onboarding notes so any competent team can take over — including a competitor of ours.

Engineering controls

How we work securely day to day

Standard, unexciting practice applied consistently — which is what security in delivery actually is.

  • Least-privilege access, reviewed at every phase change
  • Secrets in managed vaults — never in code or tickets
  • Peer review and CI checks required on every change
  • Dependency and vulnerability scanning in the pipeline
  • Environment separation with no production data in test
  • Audit logging on privileged operations by default

Data handling

  • Minimum necessary access.

    We prefer anonymised or synthetic data for development and request production access only where an issue requires it, time-boxed and logged.

  • No third-party model training.

    Client data is never used to train external models. Where AI features are built, data flows are documented and approved.

  • Regulated environments.

    We work within existing client frameworks — including sector controls in financial services and healthcare — rather than asking for exceptions.

Due diligence

Ask us the hard questions early.

Security review, IP terms and exit provisions are faster to settle before an engagement than after it. We will send our standard positions on request.

Next step

Need our security and IP positions?

Tell us your review requirements and we will send documentation ahead of any commercial conversation.