Skip to content
Assess my app Let's talk

Cookie preferences

Choose which categories you allow. You can change this any time from “Cookie settings” in the footer.

Trust & security

Trust you can verify.
No certifications we don’t hold.

This page describes, precisely, how we handle our clients’ code, data and access — and what this website does with the information you leave here.

How does Ciancoders protect client code and data?
With confidentiality agreements before seeing any code or data; by working in the client’s repository and infrastructure with access the client can revoke; with human review of every change, whether written by a person or an AI agent; with secrets kept out of the code, encryption in transit and at rest, and minimization of personal data; and with a defined incident-response procedure. Ciancoders, founded in 2015 in Quetzaltenango, Guatemala, does not publish SOC 2, ISO 27001 or cloud certifications it has not verified it holds.

How we work with your code and data

Security approach
Security is part of Cian-OS, not a final phase: threat modeling happens in Foundation, before building; security checks, static analysis and dependency review happen in Verify, on every change; observability and incident response happen in Operate. The ten concrete practices are on Quality & security.
Confidentiality and NDAs
We sign confidentiality agreements before seeing your code, data or business processes. If you have your own template, we work from it.
Code ownership
The code, documentation and deliverables of your project belong to you. We work in your repository and your infrastructure; in the Cian-OS™ Product Blueprint, the deliverables are yours whether or not you build with us.
Data handling
We apply personal-data minimization, server-side permission checks, and encryption in transit and at rest. Production data stays in your infrastructure; when a project needs data for development or testing, we agree with you what is used and how it is anonymized.
AI-assisted development
We use professional AI-assisted engineering tools. The context agents receive — conventions, constraints, decisions — is written and versioned in your repository. Agents work on bounded tasks with explicit limits. No sensitive client data is used to train models; which tools are used and under what terms is agreed with you before starting.
Human review
No change reaches the main branch without an engineer reviewing it and being able to explain it. Accountability for every relevant decision — architecture, security, acceptance — sits with a named person.
Access control
Least-privilege access, granted by you in your own tools (repository, cloud, systems) and revocable at any time. When a project ends, access is removed.
Secrets handling
Keys and credentials kept out of the code: in environment variables or secrets managers, rotated when appropriate. Never in repositories, messages or shared documents.
Backups and operations
For systems we operate under Software Care, backups, monitoring, security patches and cloud-cost review are part of the plan. For build projects, production readiness includes an explicit checklist covering deployment, backups, monitoring and documentation.
Incident response
A defined procedure: who responds, how fast, how it is communicated and what is learned afterward. On the Growth and Pro Software Care plans, critical-incident response is committed within 4 business hours, with the definition of “critical incident” published on the Operate page.

Privacy by design

Explicit consent
This site’s analytics and marketing tools require explicit opt-in; they are off by default.
No consent wall
Rejecting non-essential cookies does not limit access to the public site.
Forms excluded from recordings
Microsoft Clarity is not loaded before “Analytics” is accepted. When active, the Software Readiness Assessment, the booking form and the calendar are masked in recordings and form fields are hidden.
Reversible decision
You can change your decision at any time from “Cookie settings” in the footer.
Loaded only when needed
Third-party services load only when you use them (scheduling) or have accepted them (analytics, marketing).

Providers behind this website

What ciancoders.com actually uses to run. Our clients’ project infrastructure is each client’s own, not this list.

Cloudflare
Site hosting (Workers, static assets) and delivery network.
Cal.com
Call scheduling. Loaded only when you interact with a booking button.
Web3Forms
Email delivery of the site’s forms (Software Readiness Assessment).
Analytics and marketing (only with your consent)
Google Analytics 4 (Consent Mode, anonymized IP) and Microsoft Clarity as analytics; Meta Pixel and Apollo as marketing. They load only if configured and you accept them in the cookie notice.

Security contact

If you find a vulnerability on this site or in a system we operate, write to ventas@ciancoders.com with the subject “Security”. We confirm receipt and let you know the outcome.

What we don’t claim

We don’t publish SOC 2, ISO 27001, cloud or security certifications we haven’t verified we hold. If your project requires a specific certification, we discuss it before starting and design the project to meet it.

External references

Public frameworks that serve as reference for the practices above. Cian-OS is Ciancoders’ own methodology; these sources neither endorse nor certify it.

Trust is built from verifiable details.

Ask us about any of them.

Tell us what you're trying to solve. We'll help you decide whether to build, rescue, extend your team — or take a different path.

30 minutes · No commitment · English or Spanish