Your code and accounts stay yours
Your repositories, cloud accounts, domains and documentation belong to you from day one. You control our access, and handover is documented.
Company registration details, examples of our security practices, and information for your supplier review.
Registered details for your supplier records.
You retain ownership of your project accounts and code. The security examples below come from Popup Pal, our own product. They describe specific engineering controls, not a certification or an independent audit.
Your repositories, cloud accounts, domains and documentation belong to you from day one. You control our access, and handover is documented.
Popup Pal checks identity and permissions on the server. Venue partners can only access events assigned to them. Public forms use server-verified bot checks. Rate-limited requests are refused if the shared rate-limit store is unavailable in production.
Popup Pal limits sign-in attempts inside its credential check. Email codes are hashed, single-use and limited to five attempts. Changing an email address or password invalidates existing sessions. Sensitive credential changes require a sign-in within the previous 15 minutes.
Popup Pal uses Stripe Checkout for card entry. Payment notifications are signature-checked, matched against the expected amount and currency, and checked for duplicates. Checkout and refund requests use idempotency keys to prevent a retry being applied twice. These controls are not a PCI attestation.
Popup Pal validates incoming data on the server and escapes text in emails and structured data. CSV exports neutralise spreadsheet formulas. New compliance-document uploads use private storage, with permission checks on downloads and limits on file types and sizes.
Popup Pal pull requests run lint, unit tests, database integration tests, a dependency audit and a production build. High or critical dependency vulnerabilities fail the pipeline. Security-critical packages use exact versions. Browser tests run against staging, outside this pipeline.
Popup Pal checks its three application secrets for length and uniqueness and guards against mixed live and test payment keys. Browser headers restrict framing and unused features, with exceptions for intended embeds. A strict script Content Security Policy remains an open item in our security review.
Popup Pal sends error reports using an allowlist of fields. Messages are scrubbed of email addresses, IP addresses, URLs and tokens before sending. Session replay and tracing are switched off.
Popup Pal's dated security reviews record what was checked locally, what was verified on the hosted system and what remains open. They are internal reviews, not independent penetration tests. On client work, any review notes we produce are kept in your repository.
Tell us what your procurement or security team needs to assess CodeHardy.
Include your requirements in your enquiry, or email marcos@codehardy.com.
Send us your requirements or supplier questionnaire. We reply within one working day.