Mehvexa

Legal

Security

We treat client data and our own systems with the care a 16-year engineering practice owes them. If you find a security problem in this site or in software we run, email security@mehvexa.com and we will acknowledge it within two business days.

Last reviewed — 30 September 2026

Reporting a vulnerability

Send reports to security@mehvexa.com with enough detail for us to reproduce the issue: the affected URL or system, the steps you took and what you observed. We acknowledge every report within two business days, tell you what we intend to do, and let you know when it is fixed. We ask that you give us a reasonable window to remediate before publishing, that you do not access or modify data beyond what is needed to demonstrate the issue, and that you do not run denial-of-service tests. We will not take legal action against anyone who reports in good faith under these conditions. We do not currently pay bounties, but we will credit you if you want us to.

How we handle client data

Access to client systems and data is granted per engagement, to named engineers, on the minimum they need, and is reviewed when people join or leave a project. Every account uses multi-factor authentication and access is logged. Data in transit is encrypted with TLS 1.2 or higher, and data at rest is encrypted using the native encryption of the cloud platform it lives on, whether AWS, Google Cloud or Azure. Production data is not copied to laptops or to development environments; where realistic test data is needed we generate or anonymise it. We sign an NDA on request before any data is shared. When an engagement ends, we hand over credentials, revoke our own access, return or delete any client data we hold, and confirm that in writing.

Certifications

Mehvexa Technologies does not currently hold a third-party security certification, and we do not claim one. Our internal controls for access management, change control, incident response, supplier review and business continuity are aligned with ISO 27001 controls and are reviewed annually. Where a client requires a certified standard for a particular engagement, we can work within the client’s own certified environment and controls, and we will say plainly if a requirement is one we cannot meet. Our cloud providers, AWS, Google Cloud and Azure, each hold their own certifications, which cover the infrastructure layer of the systems we build on them.

Tell us what you are building.

A 30-minute call with an engineer who will work on it.

Book a consultationor email us directly