Security
Last updated 29 July 2026
01 — Access control
Access to client systems, repositories, and credentials is scoped to the engineers actively working on your engagement, time-boxed to the engagement itself, and revoked on handover or termination. We use two-factor authentication on all accounts with access to client infrastructure.
02 — Code & data handling
Client code lives in your own repositories from day one, not ours. Where we require temporary access to production data for debugging or testing, that access is logged, scoped to what's necessary, and never copied into our own environments.
03 — Confidentiality by default
Every engagement is treated as confidential by default, whether or not a formal NDA is signed. A mutual NDA is available on request before any detailed scoping conversation — just ask.
04 — Infrastructure practices
Where we set up or manage infrastructure on your behalf, we follow standard security practices: least-privilege access, encrypted credentials storage, and no shared logins across clients or team members.
05 — Reporting a concern
If you believe you've found a security issue in a system we've built, or in this site, please report it to [email protected]. We take reports seriously and will respond within one business day.
06 — Contact
Oxlabs, Bay Square, Business Bay, Dubai, United Arab Emirates. Written enquiries to [email protected].