Skip to content

Trust & compliance

Written for procurement, legal and security — the people who can stop a deal and are usually handed a slide instead of an answer.

We distinguish between certified and aligned to. Those are different words and your reviewers know it.

01

Data residency & hosting

Client workloads are deployed to the region the client specifies, and residency is written into the statement of work rather than assumed. We commonly operate in AWS af-south-1, eu-west-1 and me-south-1. Where a workload must not leave a jurisdiction, we architect for that from the first commit — including log and backup destinations, which is where residency commitments usually break.

  • Region specified per engagement and contractually recorded
  • Logs, backups and telemetry held in the same jurisdiction as primary data
  • No production data copied to developer machines, enforced by access design
02

Security posture

Our engineering practice is built to pass enterprise vendor review, and we will complete your security questionnaire rather than asking you to accept a summary page.

  • Encryption in transit (TLS 1.2+) and at rest as a default, not an option
  • Least-privilege access, time-bound and reviewed quarterly
  • Mandatory MFA and managed devices for all personnel
  • Documented offboarding with access revocation inside one business day
  • Dependency and secret scanning in every pipeline
  • Annual third-party penetration testing, summary available under NDA
03

Intellectual property

Stated plainly, because ambiguity here stalls deals: you own everything we build for you. IP in deliverables assigns to the client on payment, with no residual licence retained by us and no obligation to credit the work.

  • Full assignment of deliverable IP to the client
  • Pre-existing Acorn tooling is either licensed perpetually and royalty-free, or excluded and disclosed in the SOW
  • Open-source usage inventoried per project with licence compatibility reviewed
04

Compliance alignment

We distinguish carefully between frameworks we are certified against and frameworks our practice is aligned to. Current certification status is confirmed in writing during vendor review.

  • Kenya Data Protection Act 2019 — operational compliance
  • GDPR — data processing agreement available, EU representation where required
  • ISO 27001 — practice aligned; certification status confirmed under vendor review
  • SOC 2 Type II — controls mapped; status confirmed under vendor review
  • PCI DSS — scope-limited engagements supported alongside certified processors
05

Contracting & jurisdiction

We contract as a registered legal entity and carry professional indemnity cover. Governing law is negotiable — we regularly execute under English law for international clients where that is what your legal function requires.

  • Registered entity with audited financials available under NDA
  • Professional indemnity and cyber liability cover in place
  • Governing law and dispute forum negotiable per MSA
  • Named contract, security and escalation contacts for every engagement
06

Continuity

The question behind every vendor review is what happens if we disappear. The answer is designed into how we work.

  • All code, infrastructure definitions and documentation in client-owned repositories from day one
  • No single-person dependencies: minimum two engineers familiar with every system
  • Runbooks and architecture decision records maintained as delivery scope
  • Documented exit and handover plan available at any point in the engagement
The question behind every vendor review is what happens if we disappear. We answer it in the architecture, not the contract.

Code, infrastructure definitions and documentation live in your repositories from the first commit. No system we build depends on one person’s knowledge, and a written handover plan exists from day one rather than being assembled during an exit. Vendor concentration risk is a legitimate concern, and the honest response is to make ourselves replaceable.

Vendor review pack

Available on request under NDA: penetration test summary, insurance certificates, data processing agreement, standard MSA, audited financials, and named security and escalation contacts.

Send your own security questionnaire and we will complete it. We do not ask clients to accept a summary in place of their process.

Security contact: hello@acorncodelab.com

Common questions

01

Where is client data hosted, and can it stay in our country?

Client workloads are deployed to the region the client specifies, and data residency is written into the statement of work rather than assumed. Acorn Code Lab commonly operates in AWS af-south-1, eu-west-1 and me-south-1, and holds logs, backups and telemetry in the same jurisdiction as primary data — which is where residency commitments usually break.

02

Who owns the intellectual property in work Acorn Code Lab builds?

The client does. Intellectual property in deliverables assigns to the client on payment, with no residual licence retained by Acorn Code Lab and no obligation to credit the work. Any pre-existing studio tooling is either licensed perpetually and royalty-free or excluded and disclosed in the statement of work.

03

Is Acorn Code Lab ISO 27001 or SOC 2 certified?

Acorn Code Lab distinguishes between frameworks it is certified against and frameworks its practice is aligned to, and confirms current certification status in writing during vendor review. Practice is aligned to ISO 27001 and SOC 2 controls, and the studio operates in compliance with the Kenya Data Protection Act 2019 and offers a GDPR data processing agreement.

04

What happens to our systems if we stop working with Acorn Code Lab?

Code, infrastructure definitions and documentation live in client-owned repositories from the first commit, no system depends on a single person, and a written exit and handover plan is available at any point in the engagement. The studio treats being replaceable as a design requirement rather than a risk.

05

Will Acorn Code Lab complete our security questionnaire?

Yes. Acorn Code Lab completes client security questionnaires rather than asking clients to accept a summary page, and provides a vendor review pack under NDA containing penetration test summaries, insurance certificates, a data processing agreement, the standard master services agreement and audited financials.

We would rather fail your review early than waste a quarter of your time.