Security & Trust
Security Built Into Every Engagement.
NativeCode applies practical safeguards to protect client information, control system access, and reduce risk across consulting, analytics, content, and digital-growth engagements.
Our access is limited to what is necessary for each engagement, and client systems remain under the client's control unless access is expressly granted.
Our Security Approach
Limited Access
NativeCode does not require access to client systems by default. When access is necessary, it is limited to approved systems and the minimum permissions required.
Identity Protection
Company accounts use strong passwords and multifactor authentication where supported.
Secure Devices
Client work is performed on company-managed Apple devices protected by built-in macOS security controls, device encryption, screen locking, and current software updates.
Data Minimization
NativeCode collects and accesses only the information needed to perform the agreed services.
Controlled Sharing
Client information is not shared with unauthorized third parties or uploaded to external platforms or generative AI tools without authorization.
Confidentiality
Client information is handled as confidential and used only for the purposes of the engagement.
Access Is Limited by Design
NativeCode primarily provides SEO, AEO, GEO, content strategy, analytics, reporting, and consulting services.
System access is not required by default. When a client chooses to grant access, permissions are limited to the approved scope of work.
Read-only access is preferred where available
Individually assigned accounts are used
Multifactor authentication is enabled where supported
Shared credentials are avoided
Client access can be revoked by the client
No access to payment-card information
No access to customer records unless expressly required and authorized
Content is generally handed to the client for publication
Publishing access is used only when specifically granted
Device Security
Operating Systems
Client work is performed on supported versions of macOS.
Built-In Protections
Apple XProtect, Gatekeeper, FileVault encryption, System Integrity Protection, firewall, and automatic security updates.
Device Access
Devices are protected by Touch ID or strong device authentication.
Screen Locking
Screens lock automatically after inactivity, within 15 minutes or less.
Software Updates
Operating-system and application updates are installed promptly. Critical security updates are targeted within seven days or sooner depending on severity.
Business Use
Client work is performed on NativeCode-managed devices used for business purposes.
Identity & Access Management
NativeCode uses Google Workspace for business identity and account management. Access is assigned based on business need and removed when no longer required.
Multifactor authentication on company accounts
Strong password requirements, with a minimum of 12 characters
Unique user accounts for each individual
Least-privilege access based on business need
Prompt removal of access when no longer required
No routine sharing of passwords
Client-required VPN or trusted-device software can be installed when required for an engagement
Client Data Handling
NativeCode may receive limited access to analytics, search-performance, content, or business information when authorized by a client. Access is limited to the information required to perform the engagement.
Google Search Console access, when granted, is normally read-only
Google Analytics access, when granted, is normally read-only
Client data is not downloaded or retained unless necessary
Client data is not sold
Client information is not used to train public AI models
Confidential client information is not uploaded to external generative AI platforms without authorization
NativeCode does not require access to PCI or payment-card data
NativeCode does not move or commit client funds
Security Governance
NativeCode maintains documented practices covering the following areas:
Information security
Access control
Passwords and MFA
Acceptable use
Data handling and confidentiality
Incident response
Device and software security
Vendor and third-party access
Certifications
NativeCode is not currently certified under SOC 2 or ISO 27001. Our security practices are designed to be appropriate for the nature and scope of our consulting services, and we cooperate with client security and procurement reviews.
Incident Response
NativeCode maintains a process to identify, assess, contain, and respond to suspected security incidents. When an incident materially affects client information or systems, the affected client will be notified promptly in accordance with contractual and legal requirements.
01
Identify
02
Contain
03
Investigate
04
Remediate
05
Notify
06
Review
Security Documentation
Security documentation may be shared with clients and authorized procurement or security reviewers upon request.
Information Security Policy
Access Control Policy
Password & MFA Policy
Acceptable Use Policy
Data Handling & Confidentiality Policy
Incident Response Policy
Security Overview
Frequently Asked Questions
Does NativeCode require access to client systems?
No. Access is not required by default. If access is necessary, it must be expressly approved by the client.
What type of system access does NativeCode typically use?
Read-only access is preferred for analytics and search-performance platforms whenever possible.
Does NativeCode access payment-card data?
No. NativeCode does not require access to PCI or payment-card data for its standard services.
Does NativeCode use multifactor authentication?
Yes. MFA is used for supported company accounts and client systems.
Is NativeCode SOC 2 certified?
No. NativeCode is not currently SOC 2 certified.
Is NativeCode ISO 27001 certified?
No. NativeCode is not currently ISO 27001 certified.
Does NativeCode upload client information to generative AI systems?
Confidential client information is not uploaded to external generative AI systems without client authorization.
Can NativeCode comply with client VPN or trusted-device requirements?
Yes, when required and technically appropriate for the engagement.
How can a security team request additional information?
Contact security@nativecode.ai and our team will respond to reasonable security, procurement, and vendor-risk questions.
Need to Complete a Security Review?
Our team can provide additional documentation and respond to reasonable security, procurement, and vendor-risk questions.
