Trust Center
Trust Center
The things you would otherwise have to ask for.
Choosing someone to build and secure your systems should turn on evidence rather than adjectives. This page collects what a serious buyer checks before signing: who we are, who is accountable, how the work is produced, what you own when it ends, and what happens when something goes wrong.
Who you would be contracting with.
Entity details are published as they are confirmed. A field left blank here is a field we have not yet been able to state precisely, not one we are withholding: for procurement or supplier onboarding, ask and we will send the full details directly.
- Trading as
- RegenByte
- General enquiries
- [email protected]
- Security reports
- [email protected]
- Working languages
- English, Arabic, French
Your accounts. Your infrastructure. Your code.
This is a standing commitment rather than a negotiating position. An agency that holds your domain, your hosting or your repository is an agency you cannot leave, and that arrangement benefits us at your expense.
You own the source code
Everything written for you is yours, in your repository, under a licence that does not depend on us. There is no proprietary framework you have to keep paying for.
Accounts are created in your name
Wherever it is practical, the domain, hosting, DNS, cloud, repository, analytics, payment provider and third-party services are set up in your own accounts, with us added as a collaborator rather than as the owner.
Access is transferable, not hostage
Deployment credentials, environment variables and administrative access are documented and handed over. Removing our access should be one afternoon of work, not a negotiation.
Documentation written for a successor
Architecture notes, runbooks and decisions are written so that another competent team could take the system over without speaking to us first.
No lock-in by design
We use widely adopted, well documented technology and avoid decisions whose main effect is to make us hard to replace. Choosing to stay with us should be a judgement about the work.
Maintenance is optional
Ongoing support is offered because systems need it, not because your site stops working without us. Some clients take delivery in house, and we hand over documentation for exactly that.
Where a client asks us to host or administer something on their behalf, that is recorded in writing along with what it would take to move it back.
How we treat our own systems, and yours.
The full policy, including the responsible disclosure terms and what to expect after you report something, is on the security page. This is the summary.
- Security headers, HTTPS and transport hardening applied at the framework level so they cover every route
- Least privilege for accounts, tokens and service credentials, with administrative interfaces not left publicly reachable without reason
- Threat modelling during design, while the architecture can still change cheaply
- Testing only ever under written authorisation from the party entitled to grant it, prospective clients included
- Findings rated by real business impact rather than raw scanner severity, with remediation support and retesting included
- A published responsible disclosure policy and a machine-readable security.txt at the RFC 9116 path
Methodologies we work to
We work to these published methodologies. To be precise about what that means: these are the standards our testing and review follow, not certifications held by the company. We do not claim a formal accreditation we have not been granted.
- OWASP Top 10 and the OWASP Application Security Verification Standard (ASVS)
- OWASP API Security Top 10 for interfaces rather than pages
- The Penetration Testing Execution Standard (PTES) for engagement structure
- NIST guidance on secure development and incident handling
- CIS Benchmarks for platform and server configuration
What this site collects, and for how long.
The full detail is in the privacy policy. This is the short, honest version.
What is collected
Only what you enter in the enquiry form: your name, company, email, an optional phone number and country, and what you write about the project. There is no advertising tracking on this site.
Why it is kept
To reply to you and to keep a record of the conversation. Enquiries are stored before delivery is attempted so a mail provider outage cannot lose one.
Who can see it
RegenByte staff who need it to respond, plus the subprocessors listed above in the course of hosting, storing and delivering the message.
How to have it deleted
Email us and we will delete your enquiry and confirm when it is done. You do not have to give a reason and it does not affect anything else.
Client project data
During an engagement we work inside your systems under your access controls. We do not copy production data to our own machines when a redacted or synthetic sample will do the same job.
Findings and reports
Security findings about your systems are confidential to you. They are not published, reused as marketing, or shared with anyone else without your written permission.
Policies and machine-readable endpoints.
Everything above, in the form a lawyer, a procurement team or a crawler would want it.
- Security and responsible disclosureOur security practices and how to report a vulnerability safely.
- Privacy PolicyWhat personal data is collected, why, and your rights over it.
- Terms and ConditionsThe terms under which this website and our services are provided.
- Cookie PolicyWhat is stored in your browser and what it is used for.
- Accessibility StatementThe standard we build to and where we know we fall short.
- How we workEngagement models, delivery principles and how pricing is set.
Machine-readable
- security.txt
RFC 9116 security contact and policy location.
- llms.txt
An index of this site written for AI assistants.
- sitemap.xml
Every indexable URL, in all three languages.
Security questionnaires and supplier onboarding
If your procurement process needs a completed security questionnaire, a data processing agreement, insurance details or entity documents, send it to us and we will complete it. We will answer what is true and leave blank what is not, which is usually faster than it sounds.
Still want to check something?
If there is a question this page does not answer, ask it directly. A supplier that cannot answer questions about its own practices is telling you something.