Security
How we build, operate and protect the systems and data our clients trust us with.
Last updated: 26 August 2026
Security at Eightech
Eightech delivers managed IT, software and outsourced engineering, which means we are frequently given access to systems and data that matter to our clients. This page sets out how we approach that responsibility.
It describes practices we follow. It does not describe an audited compliance programme, because we do not have one.
Eightech does not hold ISO 27001, SOC 1, SOC 2, PCI DSS or HIPAA certification, and does not claim GDPR certification. We would rather say that plainly than imply otherwise. If a specific standard is part of your procurement process, contact us and we will tell you exactly where we stand.
Secure development
Our engineering practice is built around a few habits that matter more than any tooling:
- Changes are reviewed before they reach a production system.
- Dependencies are kept current, and updates that address known vulnerabilities are prioritised.
- Work is tested before deployment, at a depth agreed with the client for the system in question.
- Credentials and secrets are kept out of source control and out of client-side code.
- Systems are documented so that they can be operated and audited by someone other than the person who built them.
Where a client has their own secure-development requirements, we work to those.
Access control
Access to client systems is granted on a least-privilege basis: people get the access their role requires, for as long as the engagement requires it, and no more.
- Access is tied to a named individual, never a shared team login.
- Access is removed when someone leaves the engagement.
- Access to client production systems is granted by the client, on the client's terms, using the client's identity systems where they exist.
Infrastructure
This website is a set of static files. It runs no application server, no database and no backend of its own. It is served by Vercel Inc..
Client systems are a separate matter: they run on the client's own infrastructure, or on infrastructure agreed with the client per engagement. We do not describe those environments publicly.
Data protection
Data a client shares with us is used for the engagement it was shared for, and is handled under the terms of that engagement. Handling, retention and deletion are agreed in the contract rather than set by a blanket policy here — see data processing.
For the personal data this website itself collects, see the privacy policy.
Third-party services
We keep this site's third-party footprint as small as we can. It loads no analytics, no tag manager, no advertising pixels, no session recording and no chat widget. Fonts are served from this domain rather than a font CDN.
One provider is involved in running it:
- Vercel Inc. — hosting and delivery of this website.
Enquiry forms post to this site's own domain. The submission is passed server-side to Eightech's CRM, so no third-party form service receives your details and no credential is exposed in the page.
Confidentiality
Confidentiality agreements are routine and can be signed before commercial discussions go into any detail. Our people are bound by confidentiality obligations covering client information.
Reporting a vulnerability
If you believe you have found a security issue in this website or in a system we operate, please tell us at contact@eightech.com.
Please include enough detail to reproduce the issue. We ask that you give us a reasonable opportunity to address it before disclosing it publicly. We do not currently run a paid bug bounty.
Tell us what you need.
Managed IT, a dedicated team, or a product build. We reply within one business day, in English, Arabic, or French.
contact@eightech.com · Dubai, United Arab Emirates
