Last updated 18 August 2026

Security Practices

These are the working practices Equinox Shift LLC commits to on every engagement. They describe how we operate today; we hold no third-party certification and do not claim one.

01Access to your systems

  • Least-privilege by default: we request the narrowest role that lets the workflow run.
  • Named individual accounts — never shared logins — with multi-factor authentication enabled.
  • Every integration and credential we touch is listed in an access register you receive.
  • Access is revoked within 5 business days of engagement end, and we confirm revocation in writing.

02Handling client data

  • We work with the smallest sample of real data that makes the work possible, and prefer redacted samples during design.
  • Data in transit uses TLS; data at rest sits in the client's own systems or in access-controlled business accounts we administer.
  • We do not copy client data to personal devices or unmanaged storage.
  • Operational data we processed is returned or deleted within 30 days of engagement end.

03AI components

Where a workflow uses a third-party model provider, we tell you which provider and what data reaches it before anything is built, and we prefer configurations that exclude your data from provider training. Human approval stays in place for contracts, payments, and client records until accuracy is benchmarked and you approve unattended operation in writing.

04Our own systems

  • Managed laptops with full-disk encryption and automatic screen lock.
  • Password manager for all business credentials, multi-factor authentication on email, code, and cloud accounts.
  • Dependency updates reviewed on a regular cadence for anything we deploy.

05Subcontractors

We do not place subcontractors on an engagement without your written approval. Any approved subcontractor is bound to the same confidentiality and access terms we are.

06Incident response

  • We notify affected clients without undue delay and within 72 hours of confirming an incident involving their data.
  • Notification includes what happened, what data was involved, what we have done, and what we recommend you do.
  • We provide a written post-incident summary once the investigation closes.

07Reporting a vulnerability

If you believe you have found a security issue in this website or in something we built for you, email security@equinoxshift.com with the details and steps to reproduce. We acknowledge reports within 2 business days and will keep you updated until the issue is resolved. Please do not access data that is not yours or run tests that degrade service for others.

08Security questionnaires

We are happy to complete your vendor security questionnaire before kickoff and to sign a mutual NDA and a data processing agreement where required.