Trust you can verify.
No certifications we don’t hold.
This page describes, precisely, how we handle our clients’ code, data and access — and what this website does with the information you leave here.
- How does Ciancoders protect client code and data?
- With confidentiality agreements before seeing any code or data; by working in the client’s repository and infrastructure with access the client can revoke; with human review of every change, whether written by a person or an AI agent; with secrets kept out of the code, encryption in transit and at rest, and minimization of personal data; and with a defined incident-response procedure. Ciancoders, founded in 2015 in Quetzaltenango, Guatemala, does not publish SOC 2, ISO 27001 or cloud certifications it has not verified it holds.
How we work with your code and data
- Security approach
- Security is part of Cian-OS, not a final phase: threat modeling happens in Foundation, before building; security checks, static analysis and dependency review happen in Verify, on every change; observability and incident response happen in Operate. The ten concrete practices are on Quality & security.
- Confidentiality and NDAs
- We sign confidentiality agreements before seeing your code, data or business processes. If you have your own template, we work from it.
- Code ownership
- The code, documentation and deliverables of your project belong to you. We work in your repository and your infrastructure; in the Cian-OS™ Product Blueprint, the deliverables are yours whether or not you build with us.
- Data handling
- We apply personal-data minimization, server-side permission checks, and encryption in transit and at rest. Production data stays in your infrastructure; when a project needs data for development or testing, we agree with you what is used and how it is anonymized.
- AI-assisted development
- We use professional AI-assisted engineering tools. The context agents receive — conventions, constraints, decisions — is written and versioned in your repository. Agents work on bounded tasks with explicit limits. No sensitive client data is used to train models; which tools are used and under what terms is agreed with you before starting.
- Human review
- No change reaches the main branch without an engineer reviewing it and being able to explain it. Accountability for every relevant decision — architecture, security, acceptance — sits with a named person.
- Access control
- Least-privilege access, granted by you in your own tools (repository, cloud, systems) and revocable at any time. When a project ends, access is removed.
- Secrets handling
- Keys and credentials kept out of the code: in environment variables or secrets managers, rotated when appropriate. Never in repositories, messages or shared documents.
- Backups and operations
- For systems we operate under Software Care, backups, monitoring, security patches and cloud-cost review are part of the plan. For build projects, production readiness includes an explicit checklist covering deployment, backups, monitoring and documentation.
- Incident response
- A defined procedure: who responds, how fast, how it is communicated and what is learned afterward. On the Growth and Pro Software Care plans, critical-incident response is committed within 4 business hours, with the definition of “critical incident” published on the Operate page.
Privacy by design
- Explicit consent
- This site’s analytics and marketing tools require explicit opt-in; they are off by default.
- No consent wall
- Rejecting non-essential cookies does not limit access to the public site.
- Forms excluded from recordings
- Microsoft Clarity is not loaded before “Analytics” is accepted. When active, the Software Readiness Assessment, the booking form and the calendar are masked in recordings and form fields are hidden.
- Reversible decision
- You can change your decision at any time from “Cookie settings” in the footer.
- Loaded only when needed
- Third-party services load only when you use them (scheduling) or have accepted them (analytics, marketing).
Providers behind this website
What ciancoders.com actually uses to run. Our clients’ project infrastructure is each client’s own, not this list.
- Cloudflare
- Site hosting (Workers, static assets) and delivery network.
- Cal.com
- Call scheduling. Loaded only when you interact with a booking button.
- Web3Forms
- Email delivery of the site’s forms (Software Readiness Assessment).
- Analytics and marketing (only with your consent)
- Google Analytics 4 (Consent Mode, anonymized IP) and Microsoft Clarity as analytics; Meta Pixel and Apollo as marketing. They load only if configured and you accept them in the cookie notice.
Security contact
If you find a vulnerability on this site or in a system we operate, write to ventas@ciancoders.com with the subject “Security”. We confirm receipt and let you know the outcome.
What we don’t claim
We don’t publish SOC 2, ISO 27001, cloud or security certifications we haven’t verified we hold. If your project requires a specific certification, we discuss it before starting and design the project to meet it.
External references
Public frameworks that serve as reference for the practices above. Cian-OS is Ciancoders’ own methodology; these sources neither endorse nor certify it.
- NIST SP 800-218 · Secure Software Development Framework (SSDF)Reference framework for secure development practices: review, analysis, dependency and vulnerability management.
- OWASP Application Security Verification Standard (ASVS)Verifiable application-security requirements.
- OWASP Top 10 for Large Language Model ApplicationsRisks specific to applications that integrate language models.
- NIST AI Risk Management FrameworkReference for governing risk in AI-enabled systems.
Trust is built from verifiable details.
Ask us about any of them.
Tell us what you're trying to solve. We'll help you decide whether to build, rescue, extend your team — or take a different path.
30 minutes · No commitment · English or Spanish