Trust
Security & engagement posture.
Regulators expect banks and credit unions to run due diligence on every vendor, and the liability stays with the institution. This page is written to pre-empt your questionnaire.
Statement of posture
- SSO and MFA on every account I operate; hardware keys where supported.
- Least-privilege IAM; read-only roles for audits; access scoped per engagement and revoked at close-out.
- Encryption at rest and in transit by default (KMS-managed keys, TLS 1.2+).
- Infrastructure as code (Terraform / CDK) in version control; changes are reviewable and reversible.
- Audit logs on cloud control planes and application actions; retained per your policy.
- No production data on local machines. Work happens in your environment or in isolated, encrypted cloud workspaces.
- Dependency scanning and secret scanning in CI; pre-commit secret checks.
SOC 2
I am not SOC 2 certified. I follow the AICPA Trust Services Criteria (Security is mandatory; Availability and Confidentiality as applicable) and will work inside your SOC 2 environment and controls. I complete vendor questionnaires (SIG Lite or your own) as part of any engagement. MDRM IQ’s roadmap includes a SOC 2 Type I once it has three or more bank logos.
NDA
Happy to sign yours or use mine. Mutual NDA (PDF)
Insurance
Errors & omissions and cyber liability coverage: amounts published once bound.
Background
Twenty-five years of regulated and financial-adjacent infrastructure: NIST 800-53 control implementation at a precious-metals dealer; AWS security hardening at a media research firm; identity and access programs for 7,000+ users. Code ownership transfers to the client at handoff; source escrow is available on request.
Data handling
- Regions: US-only cloud regions unless you require otherwise.
- Retention: engagement data is destroyed within 30 days of close-out, with written confirmation.
- Subprocessors: Amazon Web Services (hosting), Anthropic (LLM inference, no training on your data), Cloudflare (edge/DNS), GitHub (source control). Full list provided per engagement.
- Incident notification: within 24 hours of confirmed impact to your data.
Regulatory context
Written with the OCC/FDIC/FRB Third-Party Risk Management: A Guide for Community Banks (May 2024) and NCUA third-party guidance in mind. Request the full security packet and I will send it with the capabilities one-pager.
Request the security packet.
One email. You get the posture statement, NDA, subprocessor list, and references you can call.