This document establishes the security and privacy engineering principles adopted by Sequin Labs, Inc. for all information system implementation efforts. Rather than maintaining extensive custom documentation, we align with industry-standard frameworks while adapting them to our specific needs.
Sequin adopts the OWASP Proactive Controls as our primary security engineering reference. All software developers and system designers must adhere to these controls in their implementation work.
This framework provides concrete guidance on implementing our required secure-by-design principles:
- Minimize attack surface area
- Establish secure defaults
- The principle of Least privilege
- The principle of defense in depth
- Fail securely
- Don't trust services
- Separation of duties
- Avoid security by obscurity
- Keep security simple
- Fix security issues correctly
For additional technical guidance, developers may reference:
Sequin adopts the NIST Privacy Framework Core as our privacy engineering reference. All software developers and system designers must incorporate these principles in their implementation work.
This framework provides practical guidance on implementing our required privacy-by-design principles:
- Proactive not Reactive; Preventative not Remedial
- Privacy as the Default Setting
- Privacy Embedded into Design
- Full Functionality – Positive-Sum, not Zero-Sum
- End-to-End Security – Full Lifecycle Protection
- Visibility and Transparency – Keep it Open
- Respect for User Privacy – Keep it User-Centric
All Sequin software developers must:
- Review the referenced frameworks as part of onboarding
- Apply these principles from the earliest design phases
- Adhere to Sequin coding standards throughout the development cycle
- Participate in security and privacy reviews
Any exceptions to these principles must be documented and approved by the CEO. As Sequin evolves, we will periodically review these principles and may incorporate additional company-specific guidance.
This document will be reviewed annually to ensure ongoing alignment with industry best practices and Sequin Labs' evolving needs.
Last Updated: March 12, 2025