security
security.
last updated · may 2026
How we handle code, credentials, and client data during an engagement with Stennir.
Code and IP.
Everything we write, you own. Repository ownership transfers on day one. You can self-host. We do not retain copies after handover beyond what we need to honor the 90-day fix-it window.
We don't use client codebases to train models or seed other client engagements.
Credentials and access.
We use the principle of least privilege. Engineers get only the access required for the work. Credentials are stored in a per-engagement secrets manager, rotated at handover.
Regulated environments.
We've shipped under HIPAA, FERPA, and PCI scopes. We do not claim certifications we don't have. If your environment requires a specific compliance posture, tell us on the discovery call so we can scope it honestly.
Audit trails.
For client systems we operate or touch, we generate audit-grade event logs by default. For our own infrastructure, all access is logged and reviewed.
Incident response.
If something goes wrong, you'll hear from a named person — not a status page. Contact hello@stennir.com for any security concern. We treat these with priority.