Security Policy

Effective Date: August 2, 2026

Last Updated: August 2, 2026

1. Introduction

Security is central to the work DREOS STUDIO LLC ("DREOS STUDIO," "we," "us," or "our") performs for our Clients. Because our engagements frequently involve access to sensitive business systems — including source code, cloud infrastructure, API keys, and proprietary data — we maintain a set of security practices designed to protect Client assets throughout the engagement lifecycle. This Security Policy describes our general approach. Specific technical safeguards may be tailored per project and detailed in the applicable Project Agreement, particularly for Clients with heightened regulatory or compliance requirements.

2. Scope

This Policy applies to:

  • Information and systems DREOS STUDIO accesses while delivering Services to Clients, including credentials, cloud environments, repositories, and business data.
  • Systems and infrastructure DREOS STUDIO builds, deploys, or manages on behalf of Clients.
  • Our own internal systems used to operate DREOS STUDIO as a business.

3. Confidential Treatment of Access

Any credentials, API keys, cloud access, source code, or business information shared with DREOS STUDIO in the course of a project is treated as confidential in accordance with our Confidentiality Policy. Access to Client systems is used solely for the purpose of delivering the agreed Services and is not used, copied, or disclosed for any unrelated purpose.

4. Access Control Principles

  • Least Privilege. Where possible, we request or use only the level of access necessary to complete the assigned work, rather than broad administrative access.
  • Credential Segregation. Client credentials and access keys are kept separate from other Clients' credentials and from our own internal systems.
  • Secure Storage. Credentials and secrets are stored using secure secrets management practices rather than in plain text files or unsecured communication channels, wherever technically feasible.
  • Individual Accountability. Where a project's infrastructure supports it, we favor individually attributable access (such as named user accounts) over shared credentials, to maintain a clear audit trail of who accessed what and when.
  • Multi-Factor Authentication. Where supported by the relevant platform, we enable multi-factor authentication on accounts used to access Client production systems.
  • Revocation at Engagement End. Access to Client systems is expected to be revoked or handed back at the conclusion of an engagement, unless ongoing maintenance requires continued access under a separate agreement.

5. Infrastructure and Development Practices

Where DREOS STUDIO builds or manages infrastructure on behalf of a Client, we apply security-conscious engineering practices, which may include, depending on project requirements:

  • Use of reputable, established cloud providers for hosting and infrastructure.
  • Encryption of sensitive data in transit (e.g., via HTTPS/TLS) and, where applicable and appropriate to the project, at rest.
  • Environment separation between development, staging, and production systems, so that testing activity does not affect live systems.
  • Version-controlled source code with access restricted to authorized personnel.
  • Use of secure authentication practices for administrative access to deployed systems, such as strong password requirements and, where supported, multi-factor authentication.
  • Regular application of security patches and dependency updates where within the scope of an active maintenance agreement.
  • Input validation and standard secure-coding practices to reduce exposure to common vulnerability classes (such as injection attacks or cross-site scripting), appropriate to the technology stack in use.
  • Code review practices for significant changes prior to deployment to production environments, where team size and project scope allow.

The specific security architecture implemented for a given project depends on that project's requirements, budget, regulatory context, and the Client's own risk tolerance, and will be discussed and agreed as part of the project scope.

6. AI-Specific Security Considerations

For projects involving artificial intelligence components, we apply additional considerations relevant to AI systems, including:

  • Reviewing what data is sent to third-party AI model providers and flagging any sensitive data handling concerns to the Client before implementation.
  • Applying input sanitization and output validation practices to reduce exposure to prompt injection and related AI-specific risks, where within the agreed project scope.
  • Scoping the permissions of any AI agents capable of taking automated actions, consistent with our AI Services Terms.
  • Logging AI system interactions where appropriate, to support monitoring and troubleshooting.
  • Applying rate limiting and abuse-prevention measures to AI-facing endpoints where appropriate, to reduce the risk of resource exhaustion or unexpected cost escalation from automated misuse.

7. Third-Party Infrastructure and AI Providers

Our Services often rely on third-party infrastructure, including cloud hosting providers, AI model providers, payment processors, and other integrated services. These providers maintain their own security programs and certifications. While we select reputable providers and configure the systems we build with security best practices in mind, DREOS STUDIO does not control, and is not responsible for, the underlying security infrastructure, incident response, or data handling practices of independent third-party providers, consistent with our Terms of Service.

8. Confidentiality and Non-Disclosure

All DREOS STUDIO personnel and contractors who may access Client confidential information or systems are bound by confidentiality obligations. Information obtained through project access is not shared outside of the individuals directly working on that engagement, except as required to deliver the Services or as otherwise agreed with the Client.

9. Personnel and Access Hygiene

DREOS STUDIO applies reasonable personnel-related security practices, including:

  • Briefing team members and subcontractors on confidentiality and security expectations before granting access to Client systems.
  • Promptly deprovisioning access for any personnel or subcontractor no longer engaged on a particular project.
  • Limiting knowledge of Client-specific credentials and system details to individuals with a legitimate, project-related need to know.
  • Using secure, access-controlled internal tools for storing project documentation and communications, rather than informal or personal file-sharing methods.

10. Incident Response

In the event DREOS STUDIO becomes aware of a security incident affecting Client data or systems under our management, we will:

  1. Take reasonable steps to contain and assess the incident.
  2. Notify the affected Client without undue delay once the incident is identified and assessed.
  3. Provide available information regarding the nature of the incident, the data or systems potentially affected, and the steps being taken to address it.
  4. Take reasonable steps to remediate the underlying cause and prevent recurrence.
  5. Cooperate with the Client's own incident response process where applicable, including with respect to any legal notification obligations the Client may have to its own end users or regulators.
  6. Conduct a post-incident review, where appropriate, to identify lessons learned and any process improvements.

Because security incidents can originate from many sources — including Client-side systems, third-party providers, or factors outside DREOS STUDIO's control — this Policy describes our commitment to responsible incident handling but does not constitute a guarantee against all possible security events.

11. Client Responsibilities

Security is a shared responsibility. Clients are expected to:

  • Safeguard any credentials or access shared with them by DREOS STUDIO.
  • Promptly report any suspected unauthorized access or suspicious activity related to systems built or managed by DREOS STUDIO.
  • Maintain appropriate security practices on their own end, including secure handling of any Deliverables, staging environments, or credentials provided to them.
  • Keep any third-party accounts (e.g., cloud provider accounts, domain registrars) that remain under the Client's own ownership properly secured.
  • Promptly inform DREOS STUDIO of any personnel changes that should result in revoking a former employee's or contractor's access to shared systems.
  • Apply available security updates promptly to any systems or dependencies the Client manages independently of DREOS STUDIO.

12. Data Minimization

Where feasible, we recommend and design systems that minimize the collection and retention of sensitive data to what is necessary for the system's intended function, reducing overall exposure in the event of a security incident. We encourage Clients to avoid sharing more sensitive data or broader system access than is necessary for a given task.

13. Backups and Business Continuity

Where DREOS STUDIO manages infrastructure on behalf of a Client, and where included within the agreed project or maintenance scope, we apply reasonable backup practices appropriate to the system's criticality, such as regular automated backups of production data. The specific backup frequency, retention period, and recovery process for a given system will be documented in the applicable Project Agreement or maintenance scope. Clients with specific business continuity or disaster recovery requirements, such as a defined recovery time objective (RTO) or recovery point objective (RPO), should raise these at the outset of a project so that appropriate infrastructure can be scoped.

14. Compliance-Sensitive Projects

Certain Clients operate in regulated industries with specific compliance frameworks (such as HIPAA for healthcare data, PCI DSS for payment card data, or SOC 2 expectations for enterprise vendors). DREOS STUDIO does not represent that it holds specific third-party compliance certifications unless expressly stated in a Project Agreement. Where a project requires alignment with a specific compliance framework, this should be raised at the outset so that the appropriate architecture, providers, contractual documentation, and additional safeguards can be scoped, quoted, and, where necessary, supported by specialized third-party infrastructure providers that hold the relevant certifications.

15. No Guarantee of Absolute Security

No system, process, or organization can guarantee complete security. While DREOS STUDIO implements reasonable and industry-informed safeguards, we cannot warrant that systems we build, deploy, or manage will be immune to all forms of unauthorized access, cyberattack, or data breach. Clients operating in regulated industries should communicate applicable compliance requirements at the outset of a project so that appropriate additional safeguards can be scoped and quoted accordingly.

16. Remote Work and Device Security

DREOS STUDIO personnel and contractors work in distributed and remote settings. To reduce risk associated with distributed work, we apply reasonable practices such as requiring devices used to access Client systems to be password- or passcode-protected, encouraging the use of encrypted storage on devices that handle Client Confidential Information, and avoiding the use of unsecured public networks to access sensitive Client systems without appropriate protections such as a VPN, where practicable.

17. Audit Logging and Monitoring

Where technically supported by the platforms in use, we favor infrastructure and tools that provide activity logging for administrative actions taken on Client systems, so that a reasonable audit trail exists in the event questions arise about a specific change or access event. The extent of logging implemented for a given system depends on the platform's native capabilities and the scope agreed for that project.

18. Security Awareness

DREOS STUDIO personnel are expected to remain reasonably informed about common security risks relevant to software development and cloud infrastructure, including phishing, credential theft, and social engineering, and to apply sound judgment when handling Client credentials and sensitive information. As our team grows, we intend to formalize periodic internal security awareness practices appropriate to our size and risk profile.

19. Reviewing This Policy for Your Own Compliance Needs

If your organization needs to complete a vendor security review or questionnaire as part of onboarding DREOS STUDIO as a technology partner, we are generally able to support this process by answering reasonable, project-relevant questions about our practices, consistent with the general approach described in this Policy. Because our specific technical implementation varies by project, some vendor security questionnaire responses may need to be tailored to the particular systems and architecture involved in your engagement rather than answered generically.

20. Vulnerability Reporting

If you believe you have discovered a security vulnerability related to DREOS STUDIO's own systems or a system we manage, please report it responsibly by contacting us directly rather than disclosing it publicly. Please include a clear description of the vulnerability, steps to reproduce it if applicable, and any relevant technical details. We will review credible reports and take appropriate action, and we ask that reporters allow us a reasonable period to investigate and remediate before any public disclosure.

21. Updates to This Policy

We may update this Security Policy periodically to reflect evolving best practices, technologies, and threats. The "Last Updated" date at the top of this Policy reflects the most recent revision.

22. Contact Us

For security-related questions, concerns, or vulnerability reports, please contact:

DREOS STUDIO LLC

Wyoming, United States

Email: [Insert Contact Email]