BTB Dots
BitsToBug
Contact

BitsToBug Studios LLP

Security and Trust

Effective date: 15 July 2026Last updated: 15 July 2026

Security is engineered into how we build, not added afterwards. This page describes the controls BitsToBug Studios LLP applies across our own operations and the systems we deliver for clients.

1. Governance

  • Security responsibility sits with the founder and is exercised through documented policies covering access control, secure development, incident response, vendor management and data retention.
  • All personnel are bound by written confidentiality obligations and receive security awareness briefing on joining and periodically thereafter.
  • Access to client systems and data is granted on the principle of least privilege, reviewed on a periodic basis, and revoked promptly on role change or exit.

2. Application and infrastructure security

  • Encryption of data in transit using current industry standard protocols, and encryption at rest where the platform supports it.
  • Multi-factor authentication enforced for administrative and privileged accounts.
  • Environment separation between development, staging and production, and segregation between client environments.
  • Infrastructure provisioned as code where practicable, giving version controlled, reviewable and reproducible configuration.
  • Centralised logging, monitoring and alerting, with audit trails retained for twelve months.
  • Documented backup and restore procedures, with restoration tested periodically.

3. Secure development

  • Peer code review before merge to protected branches.
  • Automated dependency and vulnerability scanning within the delivery pipeline.
  • Secrets held in managed secret stores, never in source control.
  • Security requirements captured during discovery and carried through design, build and testing.

4. Data protection

  • Personal data processed for clients is handled strictly as a processor under a Data Processing Agreement.
  • Data minimisation applied by default, including the use of masked or synthetic data in non-production environments.
  • Retention and deletion carried out in accordance with the Privacy Policy and client instructions.
  • Support for on-premise, private cloud and India-resident deployments where a client requires data residency.

5. Compliance alignment

We build and operate in alignment with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and, where client requirements demand, the GDPR, HIPAA safeguards for healthcare workloads, and PCI DSS requirements for payment workloads. Where a client requires certification against a specific framework, this is scoped within the engagement.

6. Incident response

We maintain a documented incident response process covering detection, triage, containment, eradication, recovery and post incident review. Clients are notified without undue delay, and in any event within 48 hours, of any confirmed incident affecting their data or systems. Regulatory notification is made where required by applicable law.

7. Vendor management

Third party providers are assessed before engagement for security posture, data handling practices and contractual protections. Material sub-processors are documented, and a current list is available to clients on request.

8. Business continuity

Our delivery model is remote first with documented handover practices, source control of all work product, and no single point of dependency on any individual workstation. Client source code and infrastructure definitions are held in client owned or client accessible repositories wherever the engagement permits.

9. Reporting a security concern

Security concerns may be reported to shreyansh@bitstobug.com or support@bitstobug.com. Researchers should follow our Responsible Disclosure Policy at https://www.bitstobug.com/security/disclosure.