// // security & compliance

The buyer's security packet

Everything your security, legal, and compliance teams need for vendor due diligence — posture, controls, DPA, subprocessors, and incident response. For a signed vendor security questionnaire, contact us and we'll return it within 3 business days.

// compliance posture

Where we stand today

SOC 2 Type II alignment

We operate against SOC 2 Type II controls across security, availability, and confidentiality trust criteria. Our formal Type II audit is in progress with completion targeted for Q4 2026; the underlying control set, evidence collection, and continuous monitoring are already in production via Vanta.

GDPR & CCPA

Our standard Data Processing Addendum (DPA) covers GDPR Article 28 processor obligations and CCPA service-provider requirements. EU standard contractual clauses (SCCs) are available on request for cross-border transfers.

HIPAA

For healthcare engagements, we sign a Business Associate Agreement (BAA) and operate against HIPAA Security Rule administrative, physical, and technical safeguards. We do not process PHI outside client-approved cloud environments (typically AWS or Azure BAAs).

PCI DSS

We do not directly handle cardholder data. For engagements touching payment flows, we architect to keep PANs out of scope (tokenization via Stripe, Adyen, Braintree, or PCI-compliant gateways) and support SAQ-A / SAQ-A-EP scoping.

// controls

Security controls

Identity

SSO (Okta / Google Workspace / Microsoft Entra), MFA required for all engineers, hardware keys for admin roles.

Endpoint

Managed devices with disk encryption, EDR (SentinelOne / CrowdStrike), automated patching, and remote wipe.

Access

Least-privilege via role-based access control. Client production access is time-bound, logged, and requires explicit ticket-linked justification.

Secrets

No plaintext secrets in code or chat. Vault or cloud-native secret managers (AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) with rotation policies.

Code review

Two-person review required for merge to protected branches. Automated SAST (CodeQL / Semgrep) and dependency scanning (Snyk / Dependabot) on every PR.

Data at rest

AES-256 at rest via managed cloud KMS. Client data isolated per engagement — no shared multi-tenant storage.

Data in transit

TLS 1.2+ enforced for all client-facing and internal service-to-service traffic. mTLS for service meshes where architecturally appropriate.

Logging & audit

Centralized log aggregation with 90-day hot retention and 1-year cold retention. Immutable audit trail for privileged access events.

Backups

Automated daily backups with point-in-time recovery. Quarterly restore drills against a canary dataset — documented, dated, and reviewable.

Vulnerability management

Continuous dependency scanning, weekly automated pen-scan (Detectify / Intruder), annual third-party penetration test.

// incident response

How we handle security incidents

  1. 01 · Detect

    Automated alerting via Datadog + Sentry, plus 24/7 on-call rotation for managed systems.

  2. 02 · Triage

    Incident commander assigned within 15 minutes for Sev-1, 1 hour for Sev-2.

  3. 03 · Contain

    Isolate affected systems, rotate credentials, and preserve forensic evidence.

  4. 04 · Notify

    Client notification within 24 hours for any confirmed security event affecting their data, per DPA terms.

  5. 05 · Remediate

    Root-cause analysis published within 5 business days; corrective action tracked to closure.

  6. 06 · Learn

    Post-incident review with the client, blameless internal review, and control updates.

// subprocessors

Our subprocessors

The third-party services NextGen uses to operate. Client-specific subprocessors (analytics, error monitoring, email) are provisioned inside the client's own accounts and are not listed here. We notify clients 30 days in advance of any material subprocessor change.

SubprocessorPurpose
Amazon Web ServicesCloud infrastructure (client-directed regions)
Microsoft AzureCloud infrastructure (client-directed regions)
Google Cloud PlatformCloud infrastructure (client-directed regions)
GitHubSource control, CI/CD, code review
VantaContinuous compliance monitoring
1PasswordSecrets and credential vaulting
Google WorkspaceEmail, docs, calendar
SlackInternal and client communications (no PHI/PII)
SentryError monitoring and alerting
DatadogObservability and logging
// data handling

Where your data lives

Client-owned infrastructure

Production data — customer records, PHI, PII, PCI-adjacent flows — lives exclusively in infrastructure owned and controlled by the client (their AWS, Azure, or GCP account). NextGen engineers access these systems via time-bound, logged, least-privilege credentials issued by the client's IAM.

NextGen-side data

The only client data resident inside NextGen systems is what's necessary to run the engagement: contact information, contracts, source code (via GitHub), and business-level documentation. No production customer data is ever copied to NextGen systems, laptops, or personal accounts.

// faq

Frequently asked questions

Do you sign our vendor security questionnaire?
Yes. Send it to security@nextgencodingcompany.com and we'll return a signed response within 3 business days for standard questionnaires (SIG Lite, CAIQ, custom). More complex enterprise-vendor questionnaires may take 5-7 business days.
Do you sign a Data Processing Addendum (DPA)?
Yes — our standard DPA covers GDPR Article 28, CCPA service-provider terms, and standard confidentiality obligations. We're happy to sign the client's DPA instead if the terms are reasonable.
Do you have cyber liability insurance?
Yes. Certificate of insurance available on request — $5M cyber liability, $5M errors & omissions, $2M general liability.
Where are your engineers located?
By default, all engineers on U.S. client engagements are located in the United States. Nearshore (LATAM) engineers are available on request with client approval and updated DPA scoping.
How do you handle offboarding at engagement end?
Within 5 business days of engagement close: revoke all client-issued credentials, delete NextGen-side working copies of source and documentation older than retention policy, and provide a written offboarding attestation.
// request the packet

Need the signed vendor packet?

Contact us with your vendor security questionnaire, DPA, or MSA and we'll return a signed response within 3 business days. For time-sensitive procurement, mention it in the request and we'll prioritize.

// let's build something

Start your project request

Tell us what you're building — engineering capacity, AI, QA, cloud, or a fixed-scope software engagement. Our NYC team responds within one business day.

// what to expect
  • Response within 1 business day
  • 30-minute discovery conversation
  • Recommended engagement model & pricing
  • NYC-focused — in-person available
Start Project Request

Inbound sales only. All form information is encrypted in transit.