Texas Active Enterprise

Security and data protection

Your data, your code, your keys.

Most of what we build holds a client's operating record: customers, contracts, money, and the people behind them. Here is exactly how we keep it safe, and the plain version of what we are and are not.

  • 7 audited subprocessors, all listed below
  • 1 isolated environment per client
  • 72 hours to written incident notice
  • 30 days to full data export at exit
You own it
The code, the data, the domain, and the accounts are yours by contract. Everything in a system we run is exportable within thirty days of exit, no negotiation. We never hold the only copy.
One environment per client
Each client system runs in its own hosting project with its own database, its own file store, and its own credentials. Nothing is multi-tenant by default, so one client's data is never a query away from another's.
Encrypted in transit and at rest
Every page, API, and portal is served only over TLS. Databases are encrypted at rest on infrastructure independently audited under SOC 2 Type II and ISO 27001. Production secrets live in the platform's encrypted secret store, never in source code.
Verified identity, least access
Sign-in runs on a SOC 2 Type II identity provider with a verification code on every login; single sign-on through your own Microsoft or Google directory is available. A client seat sees that client's projects and nothing else. Administrative access is a named allowlist.
Card data never touches us
Payments run through Stripe, a PCI DSS Level 1 service provider. Card numbers and bank details are entered on Stripe's fields and stored by Stripe. We see a customer record and an invoice status, nothing more.
Encrypted, immutable backups
Our working environment is backed up with client-side encryption to object storage with Object Lock enabled, so a backup cannot be altered or deleted inside its retention window even by an attacker holding our credentials.
Hardened endpoints
The machines we build on run full-disk encryption, a host firewall, and passphrase-protected keys held in the system keychain. Source lives in private repositories, and no credential file has ever been committed to one.
AI tools on a short leash
We use commercial AI coding assistants whose terms exclude training on our data. They operate inside a permission layer that blocks reading production secrets, deploying to production, sending mail, or moving money. A person does those.
Rotation and revocation
Credentials are issued per project, never shared across clients, and rotated at exit and on any suspected exposure. When an engagement ends, our access to your accounts is removed and you keep the keys.

A small firm, built on audited infrastructure.

Texas Active Enterprise is a small engineering firm. We do not hold a SOC 2 report of our own, and we will not pretend to. What we do instead is build only on providers that do, keep every client in its own sealed environment, and put the controls that matter most where they belong: in your contract, in your ownership of the assets, and in how few people and tools can touch your data at all.

If your procurement or IT team has a vendor security questionnaire, send it. We answer it in full and in writing. We sign a data processing agreement and a non-disclosure agreement as a matter of course, and we will walk through the architecture of your system with your IT lead on a call.

Every provider that handles client data, and what they hold.

Nothing on this list is discretionary or hidden. Each provider is independently audited, each is bound by its own data processing terms, and each can be swapped for one your organization already trusts if your policy requires it.

ProviderRoleAttestation
VercelHosting, CDN, edge networkSOC 2 Type II · ISO 27001
TursoDatabases (encrypted at rest, US region)SOC 2 Type II
ClerkIdentity and sign-inSOC 2 Type II
StripeInvoicing and paymentsPCI DSS Level 1
Zoho MailEmail (SPF, DKIM, DMARC enforced)SOC 2 Type II · ISO 27001
Backblaze B2Encrypted offsite backups with Object LockSOC 2 Type II
GitHubPrivate source repositoriesSOC 2 Type II

Attestations are the providers’ own, current as published on their trust pages. Client systems are hosted in United States regions.

If something goes wrong, you hear it from us first.

72 hours

from confirmation to written notice.

If we confirm a security incident affecting your data, we notify you in writing within 72 hours of confirmation with what happened, what was affected, what we did, and what we recommend you do. Exposed credentials are rotated immediately, before the notice is written. We keep a written record of every incident and its remediation, and we share it with you on request.

To report a security concern about any system we build or run, email info@tx-ae.com with “Security” in the subject line. We acknowledge within one business day.

For your IT and procurement team

Ask for the written statement.

We keep a signed data protection statement that covers everything on this page in questionnaire-ready form, plus the data processing agreement and the architecture summary for your specific system. Request it and we send it the same day.

Request the statement