Our Security Rating
Code Brewery is rated Very Strong on the ProcessUnity Risk Index, the highest of its five ratings, as at August 2026.
Procurement and security teams increasingly ask suppliers to evidence their cyber posture rather than assert it. This is ours, assessed independently and kept current.
What is the ProcessUnity Risk Index?
ProcessUnity is a third-party risk management platform. Large organisations use it to assess the cyber security of the suppliers they depend on, because a supplier with access to your systems or your data is part of your own risk whether you have looked at them or not.
The Risk Index is ProcessUnity’s rating of a single organisation’s cyber risk posture. It places each organisation in one of five bands, from Very Weak to Very Strong.
What does the rating measure?
The Risk Index combines two views of an organisation.
The larger share comes from the inside: the security controls the organisation actually has in place, attested control by control against ProcessUnity’s control set.
The rest comes from the outside, and it needs no cooperation from the organisation being rated. ProcessUnity scans what is visible from the internet, looking for the entry points an attacker would look for, and draws on threat intelligence from third-party providers.
The result is scored across the areas a security team would expect to see, including application security, data protection and privacy, identity and access management, network security, vulnerability management, and incident response and business continuity.
Why does a software studio’s security rating matter to you?
Because of what you hand us. Building a customer portal, a billing system or an integration means working inside your systems, often with access to data about your customers. For the length of the project, and for as long as we support it afterwards, our security practices are part of yours.
Most businesses have no practical way to check that. Asking a supplier whether they take security seriously gets the same answer from everybody. A rating from a platform that procurement teams already use gives you something to compare.
How do we secure what we build for you?
We agree early where your data lives and who can reach it, keep production access separate from development access, and design the permission model before anyone writes a login screen. For systems that handle money or personal information, we scope independent penetration testing before launch and price it as part of the project.
The day-to-day practices are deliberately unglamorous. Dependencies get patched on a schedule rather than when something breaks. Access is removed when people leave. Backups are restored and timed, not merely configured. None of it is interesting, and that is rather the point.
Can I see the full report?
Yes. The report is confidential to Code Brewery and our clients, so we do not publish it here. Clients and prospective clients can request a copy, and we are glad to walk your security or procurement team through it.
Need it for a supplier assessment?
Contact our team to request our ProcessUnity Risk Index report.