Skip to content

How we handle your code, credentials and data

What we do on every engagement, not only when asked. If your organisation has its own security requirements, we follow those as well, and we'll say plainly if there is one we can't meet.

Last updated: 25 September 2026

01Access

  • We ask for the least access the work needs: read-only for a review or due diligence, a scoped account for a build.
  • Access is personal to the engineer using it, never a shared login.
  • At handover we remove our access, or hand it back for you to revoke, and confirm it in writing.

02Credentials and secrets

  • Secrets are never committed to code or pasted into chat or email.
  • They live in a password manager or the secret store of the environment they belong to, and are shared only through it.
  • Keys we create during a project are rotated or handed to you at the end.

03Your data

  • Client data stays in environments you approve. By default that means your own infrastructure or an EU region.
  • It is encrypted in transit (TLS) and at rest.
  • We test with sample or anonymised data wherever real data isn't needed.
  • At the end of an engagement we delete any copies we hold, unless the agreement says otherwise.
  • We sign a non-disclosure agreement before the first call on request.

04AI tools

  • AI agents write much of the first draft of the code. Every AI-generated change is read by a senior engineer before it merges, and nothing is deployed by an agent on its own.
  • Where you require it, we use AI tools only under settings where your code and data are not used to train models, or we don't use them on your code at all.
  • We tell you at the start which tools will see your code.

05What we deliver

  • Dependencies are checked against known vulnerabilities (CVEs) and patched before handover.
  • Containers run as non-root with minimal images and only the ports they need.
  • Every production deploy is preceded by a backup and can be rolled back.
  • Type checks and tests must pass before a change merges.

06If something goes wrong

If we find or suspect a security issue affecting your systems or data, we tell you the same day, with what we know, what we have done, and what we recommend. We help you meet any notification duties you have under the GDPR.

07Reporting a vulnerability

If you find a security problem in this website or in something we built, email info@afkzonagroup.lt with the details. We'll acknowledge it within two working days and keep you informed while we fix it.

Questions about this page: info@afkzonagroup.lt

Tell us what you need built.

A free 30-minute call with the engineer who would lead it. You leave with a scope outline and a price range.