Data & Security
How we protect the data our clients trust us with.
We build software for clients rather than run a consumer product of our own. Even so, we regularly handle personal data on our clients’ behalf, so protecting it is part of the job.
Security is everyone’s job
Every new Sympher and intern goes through security training during onboarding, and everyone repeats it each quarter. All employees, interns, and consultants sign a non-disclosure agreement that covers confidentiality, intellectual property, need-to-know access, and returning data when they leave.
Trusted platforms, sensible defaults
We run on Google Workspace with two-step verification required, and keep source code on GitHub and Bitbucket with history protected from deletion or rewriting. We use strong passwords and a password manager, encrypt work devices, and lock down access.
Least privilege
People get the least access they need to do their work, across cloud infrastructure, code, design tools, and communication channels. Access is reviewed rather than left open.
Prepared for the worst
We back up code and data, and run disaster-recovery tests for critical systems so we can restore from backups if one is lost.
Regular security checks
On client systems we run regular security audits and third-party penetration testing, encrypt data in transit and at rest, and fix what those checks surface.
Data privacy lives in the contract
We don't publish a standalone privacy policy. Our data-privacy commitments are made in each engagement instead. Every proposal and contract carries a data privacy and security section where we commit to follow the applicable law (the Philippine Data Privacy Act, Republic Act 10173, and Singapore’s PDPA or GDPR where a client needs it), design for privacy, limit access by role, and return or destroy data when the work ends. Where a project handles personal data we also sign a separate data-protection agreement covering breach notification and data destruction. We can share our standard clause on request, and we don’t sell data.
Safe by the time it ships
Before anything reaches users it goes through quality assurance and testing, with accessibility considered as part of the work. What we agree to build passes the ethics screen in our Vision & Values page, which rules out products that harm people.
