null systems
PackagesWhy one partnerWorkTrustTeam
Book Your Free Audit

Trust

How we keep your systems safe, recoverable and yours

We follow widely accepted industry practice, and we are plain about what we do and do not claim. Where your data lives depends on where you operate. We scope that with you during the audit.

Standards we follow

We align our practices with recognized frameworks: the NIST Cybersecurity Framework, the CIS Critical Security Controls, and OWASP guidance for web applications. We do not claim certifications we do not hold, and we will complete your security questionnaire on request.

Security practices

  • Encryption: data is encrypted in transit (TLS 1.2 or higher) and at rest.
  • Access: multi-factor authentication on all administrative access, least-privilege permissions, and individual credentials instead of shared logins.
  • Patching: security updates applied on a schedule, and critical patches applied promptly.
  • Email authentication: SPF, DKIM and DMARC configured and monitored, so your mail reaches inboxes and cannot easily be spoofed.
  • Monitoring: 24/7 uptime monitoring and alerting from Engine upward.

Backups and recovery

  • Backups follow the 3-2-1 rule: three copies, on two kinds of storage, with one offsite.
  • Backups run daily from Engine upward, and we restore on request.
  • Ecosystem clients get scheduled restore tests, so a backup is proven before you need it.

Where your data lives

United StatesUS regions by default
European UnionEU infrastructure, with a data processing agreement and GDPR-aligned handling
Gulf (UAE, KSA)In-region hosting where your regulations call for it, scoped during the audit
ElsewhereAgreed with you during the audit, based on your data requirements
For clients in the European Union, we host on EU infrastructure and handle personal data in line with the GDPR. We sign a data processing agreement, keep your data within the EU, and provide a list of our sub-processors on request.

Ownership and exit

Your domain, accounts and data stay in your name at all times. If you leave, we hand over credentials and documentation within five business days, and we do not hold anything back.

If something goes wrong

Critical incidents are acknowledged within 4 hours on Engine and within 1 hour on Ecosystem. After every critical incident you receive a written summary of what happened, what we did and what changes as a result.

Contract terms

Identity and Engine are month-to-month with 30 days' notice. Ecosystem starts with a three-month term, then runs month-to-month.

Questions

Send us your security questionnaire or ask about data location through the free audit.

Book Your Free Audit
© 2026 null systems. All rights reserved.
Project directoryTrustSample auditAboutBlog
Zero Friction.
Free audit2-Q check