Authentication done properly
Established libraries and protocols rather than hand-rolled sessions. Modern password hashing, secure cookie flags, and second factors where the data warrants it.
What we actually do, stated plainly enough that you can check it. No badges we have not earned, and no claim to certifications a company of our size does not hold.
What we do not claim. HALDIR LTD does not currently hold ISO 27001, SOC 2 or any comparable certification, and we will not display a badge suggesting otherwise. If your procurement process requires certified suppliers, tell us early — it may rule us out, and that is a fair outcome.
What follows is a description of practices we can evidence during due diligence if you ask.
01 — Our own systems
02 — In what we build
These are not optional extras that appear in a "hardening phase". They are how the first version is written.
Established libraries and protocols rather than hand-rolled sessions. Modern password hashing, secure cookie flags, and second factors where the data warrants it.
Roles defined narrowly, authorisation checked on the server for every request, and administrative capability separated from ordinary use.
Schema validation at every boundary, parameterised queries without exception, and output encoding appropriate to its destination.
Configuration and credentials injected at runtime from a secret store, distinct per environment, with production values never present on a developer machine.
Append-only records of who did what and when on anything sensitive — the thing nobody wants until an incident or an auditor makes it urgent.
Lockfiles committed, advisories checked on a schedule, and an upgrade plan that runs continuously instead of arriving as an annual emergency.
03 — Client data
The most common avoidable risk in software projects is a copy of the production database sitting on a laptop because it made testing easier.
Our default is that development and testing environments contain synthetic or pseudonymised data. Where working with real data is genuinely unavoidable, it happens inside your infrastructure, under a written data processing agreement, with the access logged and time-limited.
Where we process personal data on your behalf we act as a processor under Article 28 GDPR, and we engage a sub-processor only with your prior authorisation. Full detail is in our Privacy Policy.
The smallest attack surface we could give it. See the Cookie Policy for the single item stored in your browser.
04 — Disclosure
If you believe you have found a security issue in this website or in a system we operate, please tell us before telling anyone else. We will not take legal action against anyone who reports a genuine issue in good faith, avoids accessing or modifying data belonging to others, and gives us a reasonable opportunity to fix it.
Write to [email protected] with the subject line SECURITY, and include enough detail to reproduce the issue.
Please do not run automated scanning that degrades service for others, do not attempt denial of service, and do not access, alter or retain data that is not your own. If a report concerns a system we built for a client but do not operate, we will pass it to them and help them respond.
HALDIR LTD
Filippou, 11 Agios Dometios, 2363, Nicosia, Cyprus
Registration number: HE 459882
Security contact: [email protected]
We answer them properly, and we mark "no" where the answer is no rather than reaching for a favourable interpretation.
HALDIR LTD · HE 459882 · Nicosia, Cyprus