Information security policy
Wiener Labs builds systems that hold money, credentials and customer records. This policy describes how the studio handles that responsibility on client engagements.
Access is least privilege and time bound. We ask for the narrowest scope that lets the work happen, we use the client account rather than a shared one wherever the platform allows it, and access is revoked at handover rather than at some later tidy up.
Keys are rotated at handover. Deploy keys, signing keys, API tokens and service credentials created during an engagement are rotated when the work is delivered and the new values stay with the client. We do not keep a copy.
Client data stays in client infrastructure. Cloud accounts, databases and storage buckets are created in the client organisation and paid from the client account. Where we need production data to reproduce a fault we ask first and we prefer a redacted extract.
Onchain code is audited before mainnet. We do not deploy an unaudited smart contract to a production network, and we say so before the engagement starts rather than when the deadline arrives.
Findings are reported, not buried. If we discover a vulnerability in a client system, including one we wrote, it is reported to the client with a severity, a reproduction and a fix. If we discover one in a third party system we follow that vendor disclosure process.
Incidents get a written timeline. When something goes wrong we reconstruct what happened from logs and hand over the sequence, the cause and the remediation in writing.
