Skip to content
KORDAN

Security

Operational access deserves operational discipline.

Your team will work inside your systems and with your customers’ information. Here is how we control that access, stated plainly and without borrowed credentials.

Practices

How access is controlled.

These practices apply across engagements. Specific controls are confirmed with you during solution design, based on your systems and data.

Access

  • Least-privilege access

    Each person receives only the permissions their tasks require.

  • Individual user accounts

    No shared logins. Every action is attributable to a named person.

  • Role-based access

    Permissions mapped to roles where your systems support it.

  • Client-controlled provisioning

    Access to your systems is approved by you and can be revoked by you.

Credentials

  • MFA where supported

    Multi-factor authentication enabled on every system that offers it.

  • Managed credentials

    Credentials are stored in a password manager, never in documents or chat.

  • Password practices

    Unique, strong passwords with defined handling rules for every team member.

People

  • Confidentiality obligations

    Every team member is bound by confidentiality requirements before accessing client work.

  • Documented onboarding

    A consistent checklist covering accounts, policies and security expectations.

  • Documented offboarding

    Access revoked promptly and verified when someone leaves or changes role.

Environment & incidents

  • Company-managed equipment

    Provided where the engagement requires it, with agreed configuration standards.

  • Access revocation

    Immediate removal of access when risk or a role change requires it.

  • Incident escalation

    A defined path to report, contain and notify you about suspected security issues.

Access lifecycle

Every account has a beginning and an end.

Access is granted deliberately, reviewed regularly and removed promptly.
  1. 01

    Request

    Access needs are defined per role during solution design.

  2. 02

    Approve

    You approve access to your systems before anything is provisioned.

  3. 03

    Provision

    Individual accounts are created with MFA and least privilege.

  4. 04

    Review

    Access is reviewed periodically and when roles change.

  5. 05

    Revoke

    Access is removed promptly and confirmed at offboarding.

Transparency

What we don’t claim.

Kordan does not currently hold third-party security certifications or attestations such as SOC 2 or ISO 27001, and we don’t describe our practices as compliant with frameworks we have not been audited against.

What we can do is explain exactly how we operate, answer your security questionnaire in detail, and agree specific controls in writing as part of the engagement.

Data protection

Personal data and regulated work.

For engagements involving personal data of people in the EU or UK, appropriate contractual and data-processing arrangements can be put in place, depending on the engagement.

Some workflows, such as those involving payment card or health information, carry specific regulatory requirements. We assess these during discovery and will tell you plainly if an engagement is not a fit.

Security questions belong in the first conversation.

Tell us about your systems, data and access requirements, and we’ll explain how we would operate within them.

Book a Discovery Call

Tell us what you’re trying to build.