Security and responsible disclosure.
We design and build systems that sit between the platforms you already run. Security is part of the engineering, not a document we attach afterwards.
Cloud foundation
Multi-account setups, IAM, networking and infrastructure as code, built in your cloud account rather than ours. Data residency is set at the account boundary, not by a policy that asks people to remember where a file lives.
- EU work defaults to eu-north-1, Stockholm.
- US work defaults to us-east-1.
- Least-privilege IAM and no shared credentials.
- Infrastructure as code from the first commit.
What you own
The code is in your accounts, the infrastructure is code, and there is no proprietary lock-in on what we build for you. Handover is the end of every engagement, not an upsell: you get working systems and the code that built them — not a black box you cannot open.
What ships with the system
Observability, retries and an audit trail are part of the build, not a managed service we sell afterwards. Where a system processes documents, media or decisions, the trail records what ran, on which input, with which result. Running it day to day stays with you; we are a development company and do not take on operations.
Contact
Security questions, questionnaires and data processing terms: contact@landvex.com. You will hear back from a founder.
Reporting a vulnerability
Send a reproducible report to contact@landvex.com. Include the affected URL, UTC timestamp, browser or client version, complete response headers after redirects, and the smallest proof needed to demonstrate impact. Automated scanner output without a reproducible result is not sufficient.
- Limit testing to passive checks of the public landvex.com website.
- Do not access other people's data, disrupt services, submit spam, or test unrelated domains and systems.
- Stop and report immediately if you encounter non-public data.
- Landvex does not operate a public bug-bounty programme, and unsolicited reports do not create an obligation to pay a reward.