Zero major security incidents in nine years. Over $2.4B in TVL secured. This page explains how — our security practices, certifications, and the rigor we apply to every engagement.
0
Major incidents
Zero breaches, exploits, or material security events in nine years of operation.
$2.4B+
TVL secured
Cumulative value locked in smart contracts we’ve engineered and audited.
24hr
Incident response
Maximum time from detection to notification for any material security event.
01 / PRACTICES
Our six security disciplines.
Practices we apply to every engagement — and live by internally.
Access control
Hardware security keys (YubiKey) required for all production access. Role-based permissions with least-privilege defaults. Quarterly access reviews.
Encryption
AES-256 at rest, TLS 1.3 in transit. Customer data isolated in dedicated tenants. Hardware-backed key storage for production secrets.
Vendor security
All third-party services undergo security review. SOC 2 Type II required for data processors. Annual security questionnaires.
24hr notification SLA for material incidents. Runbooks for common scenarios. Quarterly tabletop exercises.
Security training
Mandatory security training for all team members. Annual refreshers. Regular phishing simulations and red-team exercises.
02 / COMPLIANCE
Certifications and compliance.
We invest seriously in compliance — it’s a signal of operational maturity, not a checkbox.
SOC 2 Type II
Audited annually for security, availability, and confidentiality controls.
GDPR Compliant
Full compliance with EU General Data Protection Regulation for all engagements.
CCPA/CPRA Compliant
Privacy rights honored for California residents and all applicable jurisdictions.
HIPAA (per engagement)
BAA available for healthcare client engagements. Additional controls applied.
ISO 27001 (in progress)
Currently pursuing certification. Expected completion Q4 2026.
NIST Cybersecurity Framework
All internal practices aligned to NIST CSF. Regular maturity assessments.
— RESPONSIBLE DISCLOSURE
Found something? Tell us.
We run a responsible disclosure program. Report vulnerabilities to security@itechsoftsolutions.com. We respond within 24 hours, triage within 5 days, and reward valid findings via our bug bounty.