Regulated organisations ask the same questions before they sign. Here are our answers up front.
In the region you choose. They stay there for the life of the project.
You do. It's delivered to you throughout the project, not handed over at the end.
Least-privilege access throughout, with managed certificates and credentials.
Every release is signed, scanned and approved before it reaches production.
Restore testing is automated and disaster recovery is drilled, so recovery is something we've already practised.
No. Services are built on open standards, with no provider lock-in in the application code.
Working through a security questionnaire? We're happy to go through it with you.
You'll speak with the people who'd design and build it. We'll come back with a straight answer on how we'd approach it.