Trust

Security & engagement posture.

Regulators expect banks and credit unions to run due diligence on every vendor, and the liability stays with the institution. This page is written to pre-empt your questionnaire.

Statement of posture

  • SSO and MFA on every account I operate; hardware keys where supported.
  • Least-privilege IAM; read-only roles for audits; access scoped per engagement and revoked at close-out.
  • Encryption at rest and in transit by default (KMS-managed keys, TLS 1.2+).
  • Infrastructure as code (Terraform / CDK) in version control; changes are reviewable and reversible.
  • Audit logs on cloud control planes and application actions; retained per your policy.
  • No production data on local machines. Work happens in your environment or in isolated, encrypted cloud workspaces.
  • Dependency scanning and secret scanning in CI; pre-commit secret checks.

SOC 2

I am not SOC 2 certified. I follow the AICPA Trust Services Criteria (Security is mandatory; Availability and Confidentiality as applicable) and will work inside your SOC 2 environment and controls. I complete vendor questionnaires (SIG Lite or your own) as part of any engagement. MDRM IQ’s roadmap includes a SOC 2 Type I once it has three or more bank logos.

NDA

Happy to sign yours or use mine. Mutual NDA (PDF)

Insurance

Errors & omissions and cyber liability coverage: amounts published once bound.

Background

Twenty-five years of regulated and financial-adjacent infrastructure: NIST 800-53 control implementation at a precious-metals dealer; AWS security hardening at a media research firm; identity and access programs for 7,000+ users. Code ownership transfers to the client at handoff; source escrow is available on request.

Data handling

  • Regions: US-only cloud regions unless you require otherwise.
  • Retention: engagement data is destroyed within 30 days of close-out, with written confirmation.
  • Subprocessors: Amazon Web Services (hosting), Anthropic (LLM inference, no training on your data), Cloudflare (edge/DNS), GitHub (source control). Full list provided per engagement.
  • Incident notification: within 24 hours of confirmed impact to your data.

Regulatory context

Written with the OCC/FDIC/FRB Third-Party Risk Management: A Guide for Community Banks (May 2024) and NCUA third-party guidance in mind. Request the full security packet and I will send it with the capabilities one-pager.

Next step

Request the security packet.

One email. You get the posture statement, NDA, subprocessor list, and references you can call.