Founder-led ownership
ActiveCUB3 engagements are led by senior engineers who stay close to architecture, delivery risk, and client communication.
CUB3 helps teams recover, build, and accelerate software when reliability matters. This page summarizes how we approach data protection, access control, infrastructure, AI usage, and compliance across client engagements.
Our trust model is pragmatic: clear scope, senior ownership, controlled access, documented decisions, and no certification claim unless evidence is available.
CUB3 engagements are led by senior engineers who stay close to architecture, delivery risk, and client communication.
Client work is scoped by engagement, with separated repositories, environments, credentials, and delivery documentation where applicable.
We favor code review, environment isolation, dependency hygiene, and CI/CD guardrails to make delivery predictable.
We request the minimum production data needed for the mission and prefer anonymized or lower-environment datasets when they are sufficient.
AI-assisted work is scoped by project constraints, reviewed by engineers, and handled with client confidentiality in mind.
Security questionnaires, architecture notes, and contractual documents can be shared during procurement or an active engagement.
CUB3 handles client information according to the mission scope, the data classes involved, and the contractual requirements agreed with the client.
We clarify what data is needed, whether production access is necessary, and which records should be anonymized, masked, or excluded.
Public web traffic is served over HTTPS. Client environments use transport encryption and platform-appropriate storage protections based on the selected infrastructure.
Client materials are retained only as long as needed for delivery, support, legal, or contractual purposes, then removed or handed back according to the engagement.
Security-sensitive changes, recovery operations, and AI-assisted outputs are reviewed by senior engineers before being delivered or deployed.
CUB3 adapts architecture to the business context instead of forcing a single stack. The public website and client delivery practices are designed around reliability and maintainability.
Access is treated as a delivery dependency: it must be sufficient to solve the problem, limited to the mission, and removable at the end.
CUB3 uses AI pragmatically, but not as a substitute for engineering accountability. Client constraints define what can be processed and where.
| Control | Description | Status |
|---|---|---|
| Client data in AI tools | Client data is only used with AI/model providers when the scope, data class, and provider terms are compatible with the engagement. | Scoped |
| Human-in-the-loop review | AI-assisted code, analysis, documentation, and architecture proposals remain reviewed by CUB3 engineers before delivery. | Active |
| Prompt minimization | Sensitive identifiers, credentials, raw personal data, and unnecessary production details are excluded from prompts where possible. | Active |
| Provider selection | Tooling is selected by project needs, data sensitivity, client constraints, and contractual commitments. | Project-defined |
| Traceable decisions | Material architecture and data-flow assumptions are recorded in project documentation or handover notes. | Active |
CUB3 separates active frameworks, work in progress, planned programs, and evidence available on request.
Active framework for the website and engagements: public privacy policy, data minimization, rights requests, and data processing terms by project.
NIS2 is not a certification. CUB3 monitors the relevant requirements and structures security alignment for the engagements concerned.
Quality management work in progress: process formalization, delivery traceability, reviews, and continuous improvement.
Planned: ISMS formalization, security policies, risk assessment, access control, and audit evidence.
Project-specific data processing terms can be agreed when CUB3 processes client personal data.
Procurement and vendor security questionnaires can be answered during a qualified sales or client process.
Architecture diagrams, data-flow notes, and operational runbooks are produced when they are relevant to the engagement.
For recovery and critical delivery work, incident response is handled with direct communication, scoped containment, and documented remediation.
Identify the signal, confirm impact, and separate symptoms from root causes.
Reduce blast radius, protect data, and stabilize the service before broader changes.
Escalate to the right client stakeholders with clear facts, risks, and decisions needed.
Ship the fix, document the root cause, and add safeguards that prevent recurrence.
Public documents are linked directly. Security-sensitive or client-specific documents are shared after qualification.
Public policy for personal data collected through the CUB3 website.
Rules governing access to and use of the public website.
Commercial terms for CUB3 services.
Project-specific data processing terms for engagements involving personal data.
Vendor security answers for procurement or client due diligence.
Project-level diagrams, runbooks, and delivery evidence when included in the engagement.
Short answers to the security and governance questions we expect during procurement and project scoping.
It depends on the engagement. CUB3 can work on client-controlled environments, cloud platforms, or dedicated infrastructure selected for the project. The hosting model is agreed during scoping.
Yes, when the project requires CUB3 to process personal data or meet specific vendor requirements, the relevant documents can be reviewed during the contracting process.
Only when the engagement scope, data classification, provider terms, and client constraints allow it. We minimize sensitive data and keep human review in the loop.
Offboarding includes handover of documentation, revocation or transfer of credentials, and recommendations for key rotation when sensitive access was involved.
Send security or procurement questions to contact@cub3.eu with the project context and the documents you need.
Send the project context, the document you need, and the expected timeline. We will answer with the right level of evidence for the engagement.