We build for banks. It shows.
Six of our clients are banks, insurers or public financial institutions. That's why an infosec lead sits inside every pod from day one, why production releases never leave human hands, and why we hold a certificate somebody outside this company audited.
27001
The one thing on this page
we didn't check ourselves.
Everything else here is us describing our own operation. UNIT audited this one and issued a certificate against it. On a site full of first-party claims, that is the difference worth paying attention to.
- Certificate
- Nº SGSI22 030
- Standard
- UNIT-ISO/IEC 27001:2022
- Issued by
- UNIT, Instituto Uruguayo de Normas Técnicas
- Issued
- 27 March 2026
- Valid to
- 26 March 2029
- Entity
- Takeoff Media S.R.L., Montevideo
Scope. Information technology services including custom software development, implementation of websites and mobile applications, digital communication and marketing services, and consultancy.
Download the certificateCertified against the 2022 revision of the standard · audited by Uruguay's national standards body
The infosec lead
is on the pod.
They join at design time, before a line is written, and set the constraints the definition of done has to carry: data flows, retention, what may touch a model. They review again before release and sign it off. Both reviews are on the pod's calendar from the first week.
The full model is on /how-we-work · four gates an agent never passes · production stays human
AI runs on your
written approval.
No agent goes near an engagement until you have approved it in writing, on tools you have validated. The authorization runs through a governance process that puts the guidelines into the work contract itself, where they are enforceable.
Written approval before anything runs
AI is enabled per engagement, by you, on the record. An engagement that hasn't been approved is delivered the way it always was.
Customer-validated tools only
The toolchain is agreed with you before work starts. If a tool hasn't cleared your review, it isn't in the pod.
The guidelines live in the contract
Every engagement goes through governance and authorization, and the agreed guidelines are embedded in the work contract, where they bind us the same way every other clause does.
Per engagement · on the record · enforceable
What runs
on the way out.
Three cadences. Static analysis runs continuously across every repository, the release checks run on everything we ship, and anything exposed to the web gets a penetration test on a schedule. All of it applies to the work an agent wrote.
Every repo
Everything we ship
+ major web releases
Amber steps are people. An agent can prepare the evidence for either one · every web-exposed solution is pentested annually and again on each major release
Guardrails we built
for our own agents.
Agents run under a standing policy set we've generalized and keep updating. We built it because we needed it, and it turned out to do something we didn't plan for: an agent with a narrow, well-defined operational scope produces work that needs less untangling afterward. The safety measures made the output better.
No secrets in context
Credentials never enter an agent's working context, on any engagement.
Egress on an allowlist
Network access is restricted to destinations that were approved in advance.
Writes stay in the repo
An agent writes inside the working repository and nowhere else.
Every action attributable
Each action is logged against the session that took it, so the trail survives the engagement.
The floor, on every engagement · the full control set forms part of the security review · no client gets a relaxed version
Watched here,
answered at any hour.
Wazuh across end devices, AWS observability across everything in the cloud, and layered analysis reading the telemetry for the shapes a fixed threshold goes straight past. A problem should reach a person before a client has to report it.
Wazuh
Host-level detection across the machines our people actually work on.
AWS observability
Native tooling across everything we run in the cloud, per environment.
24/7/365 on call
A standing team for security incidents. Not a rotation that starts on Monday.
Insured
Certificates of insurance covering operating risks, available on request.
Notification and escalation are written down before they're needed
Who is told, how quickly, and who it escalates to. The protocol is defined per engagement, so the first time it runs is not the first time anyone has read it.
Client-reported anomalies feed back into the checks
Anything you catch that we didn't becomes a case the pipeline tests for from then on.
Training is
on a schedule.
Security habits are the part that has to transfer intact when a delivery model changes, so the training runs on a calendar and none of it is optional.
Mandatory for every employee
All staff, every year, with no exemption by seniority or role.
Onboarding training
Before anyone reaches a client system or a repository.
Infosec huddles
Four times a year, across the company, on what has actually changed.
CVE advisories
Ad-hoc notes when a high-risk CVE or a major ecosystem event lands.