Security · ISO 27001 certified

We build for banks. It shows.

Six of our clients are banks, insurers or public financial institutions. That's why an infosec lead sits inside every pod from day one, why production releases never leave human hands, and why we hold a certificate somebody outside this company audited.

01 — Certified
ISO
27001
2022 revision

The one thing on this page
we didn't check ourselves.

Everything else here is us describing our own operation. UNIT audited this one and issued a certificate against it. On a site full of first-party claims, that is the difference worth paying attention to.

Certificate
Nº SGSI22 030
Standard
UNIT-ISO/IEC 27001:2022
Issued by
UNIT, Instituto Uruguayo de Normas Técnicas
Issued
27 March 2026
Valid to
26 March 2029
Entity
Takeoff Media S.R.L., Montevideo

Scope. Information technology services including custom software development, implementation of websites and mobile applications, digital communication and marketing services, and consultancy.

Download the certificate

Certified against the 2022 revision of the standard · audited by Uruguay's national standards body

02 — In the pod

The infosec lead
is on the pod.

They join at design time, before a line is written, and set the constraints the definition of done has to carry: data flows, retention, what may touch a model. They review again before release and sign it off. Both reviews are on the pod's calendar from the first week.

The full model is on /how-we-work · four gates an agent never passes · production stays human

03 — Authorization

AI runs on your
written approval.

No agent goes near an engagement until you have approved it in writing, on tools you have validated. The authorization runs through a governance process that puts the guidelines into the work contract itself, where they are enforceable.

GOV 01

Written approval before anything runs

AI is enabled per engagement, by you, on the record. An engagement that hasn't been approved is delivered the way it always was.

GOV 02

Customer-validated tools only

The toolchain is agreed with you before work starts. If a tool hasn't cleared your review, it isn't in the pod.

GOV 03

The guidelines live in the contract

Every engagement goes through governance and authorization, and the agreed guidelines are embedded in the work contract, where they bind us the same way every other clause does.

Per engagement · on the record · enforceable

04 — The pipeline

What runs
on the way out.

Three cadences. Static analysis runs continuously across every repository, the release checks run on everything we ship, and anything exposed to the web gets a penetration test on a schedule. All of it applies to the work an agent wrote.

Continuous
Every repo
Static code analysis Agent guardrails enforced Observability
Per release
Everything we ship
OWASP checks Infosec sign-off Human release
Yearly
+ major web releases
Penetration test

Amber steps are people. An agent can prepare the evidence for either one · every web-exposed solution is pentested annually and again on each major release

05 — Guardrails

Guardrails we built
for our own agents.

Agents run under a standing policy set we've generalized and keep updating. We built it because we needed it, and it turned out to do something we didn't plan for: an agent with a narrow, well-defined operational scope produces work that needs less untangling afterward. The safety measures made the output better.

Control

No secrets in context

Credentials never enter an agent's working context, on any engagement.

Control

Egress on an allowlist

Network access is restricted to destinations that were approved in advance.

Control

Writes stay in the repo

An agent writes inside the working repository and nowhere else.

Control

Every action attributable

Each action is logged against the session that took it, so the trail survives the engagement.

The floor, on every engagement · the full control set forms part of the security review · no client gets a relaxed version

06 — Detect & respond

Watched here,
answered at any hour.

Wazuh across end devices, AWS observability across everything in the cloud, and layered analysis reading the telemetry for the shapes a fixed threshold goes straight past. A problem should reach a person before a client has to report it.

End devices

Wazuh

Host-level detection across the machines our people actually work on.

Cloud

AWS observability

Native tooling across everything we run in the cloud, per environment.

Response

24/7/365 on call

A standing team for security incidents. Not a rotation that starts on Monday.

Transfer

Insured

Certificates of insurance covering operating risks, available on request.

IR 01

Notification and escalation are written down before they're needed

Who is told, how quickly, and who it escalates to. The protocol is defined per engagement, so the first time it runs is not the first time anyone has read it.

IR 02

Client-reported anomalies feed back into the checks

Anything you catch that we didn't becomes a case the pipeline tests for from then on.

07 — People

Training is
on a schedule.

Security habits are the part that has to transfer intact when a delivery model changes, so the training runs on a calendar and none of it is optional.

Annual

Mandatory for every employee

All staff, every year, with no exemption by seniority or role.

Day one

Onboarding training

Before anyone reaches a client system or a repository.

Quarterly

Infosec huddles

Four times a year, across the company, on what has actually changed.

As it happens

CVE advisories

Ad-hoc notes when a high-risk CVE or a major ecosystem event lands.

08 — Start