Security & Trust

Security Built Into Every Engagement.

NativeCode applies practical safeguards to protect client information, control system access, and reduce risk across consulting, analytics, content, and digital-growth engagements.

Our access is limited to what is necessary for each engagement, and client systems remain under the client's control unless access is expressly granted.

Our Security Approach

Limited Access

NativeCode does not require access to client systems by default. When access is necessary, it is limited to approved systems and the minimum permissions required.

Identity Protection

Company accounts use strong passwords and multifactor authentication where supported.

Secure Devices

Client work is performed on company-managed Apple devices protected by built-in macOS security controls, device encryption, screen locking, and current software updates.

Data Minimization

NativeCode collects and accesses only the information needed to perform the agreed services.

Controlled Sharing

Client information is not shared with unauthorized third parties or uploaded to external platforms or generative AI tools without authorization.

Confidentiality

Client information is handled as confidential and used only for the purposes of the engagement.

Access Is Limited by Design

NativeCode primarily provides SEO, AEO, GEO, content strategy, analytics, reporting, and consulting services.

System access is not required by default. When a client chooses to grant access, permissions are limited to the approved scope of work.

Read-only access is preferred where available

Individually assigned accounts are used

Multifactor authentication is enabled where supported

Shared credentials are avoided

Client access can be revoked by the client

No access to payment-card information

No access to customer records unless expressly required and authorized

Content is generally handed to the client for publication

Publishing access is used only when specifically granted

Device Security

Operating Systems

Client work is performed on supported versions of macOS.

Built-In Protections

Apple XProtect, Gatekeeper, FileVault encryption, System Integrity Protection, firewall, and automatic security updates.

Device Access

Devices are protected by Touch ID or strong device authentication.

Screen Locking

Screens lock automatically after inactivity, within 15 minutes or less.

Software Updates

Operating-system and application updates are installed promptly. Critical security updates are targeted within seven days or sooner depending on severity.

Business Use

Client work is performed on NativeCode-managed devices used for business purposes.

Identity & Access Management

NativeCode uses Google Workspace for business identity and account management. Access is assigned based on business need and removed when no longer required.

Multifactor authentication on company accounts

Strong password requirements, with a minimum of 12 characters

Unique user accounts for each individual

Least-privilege access based on business need

Prompt removal of access when no longer required

No routine sharing of passwords

Client-required VPN or trusted-device software can be installed when required for an engagement

Client Data Handling

NativeCode may receive limited access to analytics, search-performance, content, or business information when authorized by a client. Access is limited to the information required to perform the engagement.

Google Search Console access, when granted, is normally read-only

Google Analytics access, when granted, is normally read-only

Client data is not downloaded or retained unless necessary

Client data is not sold

Client information is not used to train public AI models

Confidential client information is not uploaded to external generative AI platforms without authorization

NativeCode does not require access to PCI or payment-card data

NativeCode does not move or commit client funds

Security Governance

NativeCode maintains documented practices covering the following areas:

Information security

Access control

Passwords and MFA

Acceptable use

Data handling and confidentiality

Incident response

Device and software security

Vendor and third-party access

Certifications

NativeCode is not currently certified under SOC 2 or ISO 27001. Our security practices are designed to be appropriate for the nature and scope of our consulting services, and we cooperate with client security and procurement reviews.

Incident Response

NativeCode maintains a process to identify, assess, contain, and respond to suspected security incidents. When an incident materially affects client information or systems, the affected client will be notified promptly in accordance with contractual and legal requirements.

01

Identify

02

Contain

03

Investigate

04

Remediate

05

Notify

06

Review

Security Documentation

Security documentation may be shared with clients and authorized procurement or security reviewers upon request.

Information Security Policy

Request Document

Access Control Policy

Request Document

Password & MFA Policy

Request Document

Acceptable Use Policy

Request Document

Data Handling & Confidentiality Policy

Request Document

Incident Response Policy

Request Document

Security Overview

Request Document

Frequently Asked Questions

Does NativeCode require access to client systems?

No. Access is not required by default. If access is necessary, it must be expressly approved by the client.

What type of system access does NativeCode typically use?

Read-only access is preferred for analytics and search-performance platforms whenever possible.

Does NativeCode access payment-card data?

No. NativeCode does not require access to PCI or payment-card data for its standard services.

Does NativeCode use multifactor authentication?

Yes. MFA is used for supported company accounts and client systems.

Is NativeCode SOC 2 certified?

No. NativeCode is not currently SOC 2 certified.

Is NativeCode ISO 27001 certified?

No. NativeCode is not currently ISO 27001 certified.

Does NativeCode upload client information to generative AI systems?

Confidential client information is not uploaded to external generative AI systems without client authorization.

Can NativeCode comply with client VPN or trusted-device requirements?

Yes, when required and technically appropriate for the engagement.

How can a security team request additional information?

Contact security@nativecode.ai and our team will respond to reasonable security, procurement, and vendor-risk questions.

Need to Complete a Security Review?

Our team can provide additional documentation and respond to reasonable security, procurement, and vendor-risk questions.