Security
Last updated: 15 August 2026
1. Our approach to security
Security is considered throughout the design, development and operation of Logicode solutions.
We design software around the information, users and responsibilities involved in the business process, then apply security controls appropriate to that context.
The specific controls used for a project depend on its architecture, data, integrations, user roles and operating requirements. We do not treat security as a single checklist that is identical for every implementation.
2. Security by design
Security considerations are addressed during design and development rather than left only to the final stages of a project.
Depending on the solution, this includes areas such as:
- authentication and user access
- roles and permissions
- protection of sensitive information
- validation of untrusted input
- secure handling of credentials and secrets
- data and customer separation
- third-party dependencies
- production configuration
- logging and traceability
Security-sensitive functionality receives additional attention according to the risks and business impact involved.
3. Access and permissions
Access is designed around the principle that users and systems should receive only the permissions required for their responsibilities.
Where appropriate, Logicode solutions use role-based access controls to determine who may view, create, change, approve or administer information.
Administrative access is restricted rather than granted by default.
4. Customer and data separation
Logicode designs access and data boundaries so users can reach only the information and capabilities they are authorised to use.
Where a solution is delivered in a customer-specific environment, customer data and configuration remain separated from other customer implementations.
The exact infrastructure used may vary by project. Customer separation does not necessarily mean that every implementation requires physically separate servers or cloud accounts; the appropriate isolation model is determined by the agreed architecture.
5. Logicode access to customer environments
Logicode does not require unrestricted permanent access to customer production data simply because we developed the solution.
Administrative and support access is limited to what is necessary to deliver, operate or support the agreed service.
Where practical, production access uses named accounts and appropriate permissions rather than shared credentials. Access can be reduced or removed when it is no longer required.
The objective is that access remains purposeful, restricted and based on need.
6. Credentials and secrets
Application passwords, API keys, service credentials and other secrets are kept out of publicly accessible client code and source repositories.
Secrets are handled using protected configuration or secret-management mechanisms appropriate to the selected infrastructure.
Access to credentials should be limited to the systems and people that require them, and credentials can be rotated or revoked if compromise is suspected.
7. Data protection
Production websites and applications use HTTPS/TLS to protect information transmitted between users and the application.
Stored information is protected using security controls appropriate to the sensitivity of the data and the selected infrastructure, including encryption at rest where provided or required by the architecture.
Where backups form part of the agreed operating model, they are protected against unauthorised access and configured according to the recovery requirements of the solution.
We do not apply one universal backup schedule to every project because recovery requirements differ between solutions.
8. Dependencies and maintenance
Logicode uses third-party software and infrastructure where they provide an appropriate foundation for the solution.
Dependencies are selected deliberately and can be reviewed for known security issues and maintained as the solution evolves.
Security fixes are prioritised according to their relevance, severity and the risk they present to the solution.
Ongoing maintenance arrangements depend on the applicable project and support plan rather than being assumed to be identical for every implementation.
9. Logging, traceability and monitoring
Applications are designed to record operational and security events appropriate to their purpose.
Where accountability matters, important actions such as submissions, approvals, changes or administrative activity can be associated with the responsible user and relevant context.
Logs should avoid unnecessary sensitive information and access to logging data should itself be appropriately restricted.
Production monitoring and alerting are configured according to the operating requirements of the solution and the agreed support or maintenance arrangement.
10. AI security and control
Where AI is included in a Logicode solution, the agent is designed around a defined business purpose rather than being given unrestricted access by default.
Depending on the use case, controls may include:
- approved knowledge or data sources
- explicitly permitted tools or capabilities
- limits on what the agent may access or perform
- human review before actions with meaningful business impact
The exact controls depend on what the agent is expected to do.
Logicode does not assume that every AI implementation requires the same governance, monitoring or approval model.
11. Security incidents
If Logicode becomes aware of a security incident affecting a customer solution, we investigate the issue and take reasonable steps to contain, understand and remediate it.
Affected customers are informed where required by the applicable agreement or by law.
Where an incident involves personal data, applicable data-protection requirements may impose additional assessment, documentation and notification obligations.
12. Responsible disclosure
We welcome responsible reports of suspected security vulnerabilities affecting the Logicode website or systems operated by Logicode.
If you believe you have identified a vulnerability, please report it privately and provide enough information for us to understand and reproduce the issue.
When investigating a potential vulnerability, please:
- avoid accessing information that does not belong to you
- do not copy, modify or delete data beyond what is necessary to demonstrate the issue
- do not intentionally disrupt or degrade the service
- do not use social engineering against Logicode staff, customers or service providers
- allow us an opportunity to investigate the issue before making vulnerability details public
Reporting a vulnerability does not create an entitlement to payment or a bug bounty unless Logicode has explicitly agreed otherwise.
13. Customer-specific security requirements
Some customers or projects may require controls beyond the standard Logicode approach.
These may include requirements such as:
- enterprise identity or single sign-on
- specific hosting or data-residency arrangements
- additional audit logging
- enhanced backup and recovery requirements
- vulnerability assessments or penetration testing
- advanced monitoring and alerting
- customer-specific security policies
- additional regulatory or compliance requirements
Where these requirements apply, they are identified and agreed as part of the project rather than assumed to be included in every starting package.
14. No absolute security guarantee
No software system or internet-connected service can be guaranteed to be completely free from security vulnerabilities or incidents.
Logicode applies security practices intended to reduce risk and designs controls appropriate to the solution, but security is an ongoing process that also depends on infrastructure, configuration, maintenance and how the system is operated.
15. Security questions
Questions about Logicode’s security approach or security requirements for a potential project can be raised during the initial project discussion.
Security requirements that materially affect architecture, infrastructure or delivery are confirmed as part of the applicable project scope.
For suspected vulnerabilities, report privately to hello@logicode-consulting.com.