Trust is an engineering practice. Here is how we run it.
Every CirOps engagement involves real access - to infrastructure, to configuration, sometimes to systems that run your product in production. We document and enforce our security practices the same way we engineer client infrastructure: with specificity, accountability, and no assumptions.
Agreed notification
Documented escalation
OIDC
Zero static credentials
SOC2-aligned
Best practices
Credentials & Secrets
Scoped credentials and documented access paths.
CirOps operates a vault-based secrets management practice for client engagements. Here is what that means in practice:
Vault-based secrets storage.
Credentials, API keys, and access tokens used in CirOps-managed engineering workflows are stored in Zoho Vault with role-based access, audit logging, and session-scoped retrieval. Our documented practice prohibits passing secrets through email, chat, or unencrypted channels.
OIDC machine authentication.
Where client environments support it, CirOps engineers configure and use OIDC-based authentication for machine-to-cloud access - eliminating static credentials entirely and replacing them with short-lived, cryptographically signed tokens issued per workflow run.
Temporary cloud access.
Client access is designed around provider-native roles or identities, temporary credentials, automated rotation, or OIDC federation. AWS IAM roles and STS sessions are examples of these controls.
Least-privilege by default.
Access roles scoped to CirOps engineers are defined with minimum required permissions for the specific engagement. We do not request admin-level access unless an engagement specifically requires it, and even then it is time-bound and auditable.
Data Handling
Your data stays in your environment.
CirOps engineers access client infrastructure to assess, build, and operate - not to extract. Our data handling commitment:
What we access.
During engagements, CirOps engineers access cloud console configurations, IaC definitions, log data, and cost and usage reports. We do not access application-layer data (databases, user records, payment data) unless an engagement specifically requires it, in which case access is scoped, logged, and agreed in advance.
Where it lives.
Production data remains in your cloud environments. CirOps does not copy, export, or store client data to our own systems. Any outputs we produce - IaC code, runbooks, architecture documentation - are delivered to you as part of the engagement and removed from our working environments at close.
Retention.
We retain engagement documentation (architecture notes, delivery records) only for the duration agreed in your contract. After that period, client artifacts are deleted from CirOps systems.
AI-assisted tooling and your data.
CirOps engineers use AI-assisted tools for IaC generation, cost anomaly detection, and incident root cause analysis. These tools operate on configuration and telemetry data within your environment. No client configuration data is transmitted to external AI services without your explicit, documented consent. See how CirOps works for full detail on how AI-assisted operations work in practice.
Engagement Terms
Confidentiality is standard, not optional.
CirOps signs non-disclosure agreements before any engagement begins - including initial architecture reviews and discovery calls where sensitive system details may be shared.
We work with your template or provide ours. Either way, confidentiality protection is in place before a single diagram is reviewed or a single credential is shared.
Engagement terms protect your intellectual property in the deliverables we produce. IaC code, runbooks, and architecture documentation created for your environment belong to you.
To request our standard NDA or engagement terms, contact connect@cirops.io.
Zero Trust Access
Access is granted per session, not per relationship.
CirOps applies zero-trust principles to every client environment we operate in. In practice, that means:
OIDC-based access for automation.
CI/CD pipelines, deployment workflows, and operational automation are authenticated via OIDC federation - no static credentials in pipeline configuration, no secrets checked into version control.
Short-lived credentials for human access.
Engineers access client environments through provider-native roles or identities that issue temporary credentials. AWS STS is one example. Sessions expire according to the access policy agreed for the engagement.
Just-in-time access for support operations.
For on-call and incident response, access is granted for the duration of the incident and revoked on resolution. Access events are logged with timestamps, engineer identity, and action scope.
Immutable audit trail.
Client access is recorded through the platform audit logging configured for the environment. AWS STS and CloudTrail are examples; Google Cloud and Microsoft Azure equivalents are used where applicable. Log access and retention follow the agreed engagement controls.
Incident Response
A documented path for client notification.
If a security incident occurs in a client environment during a CirOps engagement, we follow a defined response protocol:
Contain
Immediate action to limit the scope of the incident - isolating affected resources, revoking compromised credentials, or halting in-flight deployments.
Notify
Notify the named client contacts through the agreed escalation path and within the contractual notification window.
Analyze
Root cause analysis conducted in parallel with containment. We do not wait until the incident is resolved to begin investigating the cause.
Report
Written post-incident report delivered to the client: timeline, root cause, remediation actions taken, and recommended hardening steps.
You maintain incident command throughout. CirOps operates in support of your team, not around it.
Compliance Posture
Aligned to industry security frameworks.
CirOps's internal security practices are designed to align with SOC 2 Trust Service Criteria and ISO 27001 principles - covering access control, incident response, data handling, and operational security. Clients in regulated industries (fintech, health-tech) may request a security questionnaire response or a summary of our controls mapping.
This page describes CirOps's own engagement practices, including access, secrets, evidence handling, and incident response. It does not make CirOps an auditor of itself or of customers. Client delivery is described separately under Cloud Security, Cloud Compliance Readiness, and Managed Cloud Security Posture.
Certifications
Technical delivery credentials
Credentials and capability areas relevant to an engagement are confirmed during discovery.
AWS









Kubernetes





Google Cloud


Azure




HashiCorp

Common questions about security and access
Start with a no-cost Architecture Review.
If you have questions about our security practices before committing to an engagement, we are happy to answer them directly. Send questions to connect@cirops.io or request a discussion. When you are ready to move forward, the Cloud Architecture Review is a structured assessment of your current infrastructure.