VertexEngineering

Security

How we protect your data, code, and systems.

Our commitment

At Vertex Engineering, security is embedded in every stage of development. Our team includes OWASP members actively involved in the global application security community.

Secure development practices

We follow OWASP guidelines, including the OWASP Top 10 and secure coding standards. All code goes through peer review before deployment.

Data protection

We apply the following controls to protect sensitive information:

  • TLS encryption in transit
  • Encrypted storage for sensitive data
  • Role-based access control
  • Daily backups with defined retention
  • Principle of least privilege

Infrastructure

Our infrastructure and delivery pipeline follow security best practices:

  • Isolated environments (development, staging, production)
  • Secrets managed outside source code
  • Dependency vulnerability monitoring
  • Regular security updates

Confidentiality

We sign NDAs before project discovery. Client code and data remain the client's property. We never share project information with third parties without consent.

Compliance alignment

Our practices align with internationally recognized frameworks: OWASP ASVS, NIST SSDF, GDPR principles, and Uruguay Law 18.331 on personal data protection.

OWASP membership

Vertex Engineering is connected to the OWASP community. Our security contact is an active OWASP member: peter.fernandez@owasp.org

Reporting a vulnerability

If you discover a security issue in any of our systems or applications, please contact us responsibly. We appreciate coordinated disclosure.

We commit to acknowledging reports within 48 hours and keeping you informed of remediation progress.