Back to Home

Security

How we secure our own systems and, more importantly, yours. This page describes what we actually do, no invented programs, no certifications we do not hold.

Our security practices

We are a small consultancy, and our internal security is built on modern platform defaults done properly rather than a large security organisation. Our practices are informed by ISO 27001 controls; we are not certified and do not claim to be.

  • Microsoft Entra ID with MFA enforced on all internal accounts
  • Managed, encrypted work devices with automatic patching
  • Least-privilege access, reviewed when engagements start and end
  • Secrets kept in Azure Key Vault, never in code or chat
  • Encryption in transit (TLS) and at rest for everything we store

How we secure client engagements

  • Client work runs in your tenant and your subscriptions wherever possible, data stays under your control
  • Access granted through your identity provider, scoped to the engagement, and offboarded when it ends
  • Client data is not copied to our devices unless an engagement explicitly requires it, and then minimally
  • DPA and confidentiality terms as standard for every engagement
  • Security-relevant decisions documented so your team can audit what we did

Security in what we build

Most of the security value we provide is in the systems we deliver. Standard practice in our builds:

  • Managed identities over connection strings; Key Vault for what remains
  • Private networking (VNet integration, private endpoints) for AI and data services
  • Code review, dependency scanning, and infrastructure as code in CI/CD
  • Logging and telemetry (Application Insights, Azure Monitor) wired in from day one
  • For AI workloads: prompt-injection awareness, output handling, and agent permission scoping

Platform security (Microsoft’s role)

We build on Azure and Microsoft 365, which carry Microsoft’s certifications (ISO 27001, SOC 1/2/3, and more) and the EU Data Boundary. Those attest to the platform, not to us, our contribution is configuring identity, networking, residency, and logging so your workload actually benefits from those controls.

If something goes wrong

We keep this simple and honest: if we discover or are notified of a security incident affecting client data, we investigate immediately, notify affected clients without undue delay in line with GDPR, and document cause and remediation. Logging in the systems we build exists precisely so incidents can be investigated properly.

Responsible vulnerability disclosure

We welcome reports from security researchers. If you believe you have found a security issue:

  1. Email security@technspire.com with details and reproduction steps
  2. Give us reasonable time to address the issue before public disclosure
  3. Act in good faith: no data destruction, privacy violations, or service disruption

We acknowledge reports within 48 hours and credit researchers (with permission) once resolved.

Security contact

Security questions or vendor assessments: security@technspire.com, we respond within two business days.

Last updated: September 1, 2026