Trust and security.
How we treat client data, secure our infrastructure, and report incidents. The same baseline we apply to our own systems and the engagements we operate.
What we hold to.
Reactit handles operational data and credentials for regulated financial institutions. Our trust posture is shaped by that — and by the fact that we are usually on-call for the systems we touch.
Our information-security baseline is aligned to ISO/IEC 27001. It is not certified; it is audited annually by a third-party reviewer and the results are shared with clients who ask. We treat security as an engineering discipline, not a checklist.
When something goes wrong, we say so. Incidents that touch client data are reported in writing within 24 hours of detection, regardless of whether disclosure is legally required.
Six commitments.
ISO/IEC 27001-aligned
Annually audited by a third party. Findings shared with clients on request.
Least-privilege access
No standing access to client systems. Time-bound, reviewed monthly.
Secret hygiene
Rotation, scanning, and revocation built into the pipeline.
Encryption at rest & in transit
Default everywhere — no exceptions, even in lower environments.
Incident reporting
Written notice within 24 hours of detection.
Penetration testing
Annual external testing of our own platform, summary shared on request.