Your code, your IP
Work happens in your repository, under your organization, from the first commit. Every engineer signs an IP assignment before touching the code, so there's never a question of who owns what was built.
// security
The same practices that keep a payments platform and a compliance wallet in production apply to every engagement.
Work happens in your repository, under your organization, from the first commit. Every engineer signs an IP assignment before touching the code, so there's never a question of who owns what was built.
An NDA is signed before the first call that touches specifics — the problem, the stack, or the data. Nothing about your system goes into a proposal, a case study, or a conversation with another client.
Engineers get least-privilege access scoped to what their part of the system needs, and access is reviewed as engagements change shape. Offboarding revokes repository, infrastructure and credential access the same day an engagement ends.
Production secrets live in a secrets manager, never in a repository or a laptop's environment file. On systems handling real money or personal data — like a compliance wallet's AML pipeline — personal data is redacted before it reaches any model, self-hosted or otherwise, and production data doesn't leave your infrastructure to sit on an engineer's machine. For how we handle the personal data this site itself collects, see our privacy policy.
Every engineer, core or network, is vetted by WebStreaming on architecture, system design and a real code sample before they're staffed to an engagement, and works under WebStreaming's NDA and IP assignment for the length of it.
A single point of contact for access decisions, a repository we can be invited into rather than emailed a zip file, and — for anything touching production — a heads-up before credentials rotate so an incident isn't mistaken for a breach.
We are not SOC 2 or ISO 27001 certified. What we do instead is the practices on this page — least-privilege access, secrets out of repositories, redaction before any model sees personal data, and same-day offboarding — applied to every engagement whether or not it's audited. We complete your security questionnaire rather than asking you to trust a badge, and where your organization runs its own compliance regime, we work inside it: your access model, your data residency requirements, your evidence requests.
Separately, and specifically: we built and took a US payments platform through PCI DSS Level 1 service provider validation — a QSA-led onsite assessment with a Report on Compliance and a signed Attestation of Compliance — and through its PCI DSS v4.0 revalidation since, with quarterly ASV scans. That attestation belongs to the client's platform, not to WebStreaming as a company — it isn't a substitute for SOC 2 or ISO 27001, and it doesn't extend to engagements where we don't build the payments architecture ourselves. Both things are true at once: no company-wide compliance certification, and direct, hands-on experience taking a real platform through PCI DSS Level 1 validation and its ongoing revalidation.
// contracting
Entity, governing law, payment terms, IP assignment and insurance are answered in full on how we contract.
Tell us what you're building. You'll leave with an honest opinion, even if it's "you don't need us."
Reference calls with past clients are available under NDA during evaluation.