OutsourcingVN is operated by Netbase JSC, so read this as a description of our own practice as well as general guidance. It is written for the person who has to explain the arrangement to a security or procurement colleague. An accountable delivery owner running a globally sourced team makes access and data questions more important, not less, because the answer is never that everyone happens to sit in one room. If you are earlier in the decision, the Vietnam outsourcing buyer guide covers the wider question first.
What we do, and what we do not claim
Netbase's security practices include secure code review and version control, role-based access control, multi-factor authentication for admin dashboards, contributors working under NDA, and NDAs and data processing agreements available on request. Those are the practices we publish, and they are the ones we will describe in detail for a specific project.
We do not publish a security certification, and nothing on this page should be read as one. We do not claim an independent audit report, a formal attestation, or that any particular regulation applies to your project by default. If your procurement process needs an external audit or a certification scheme, ask for it directly and expect a plain answer rather than a logo. A provider that answers "yes" to every framework you name is telling you less than one that tells you which two it can actually evidence.
That distinction matters more than it sounds. Most of the security failures we see in outsourced projects are not caused by a missing framework. They are caused by an account nobody removed, a production database copied into a test environment, or a credential pasted into a chat channel.
Start with your data, not with a checklist
Before you evaluate any provider, write down what the project actually touches:
- the categories of data involved, and which of them are personal, financial or regulated;
- whether the team needs production data at all, or can work with masked or synthetic data;
- which existing systems the work connects to, and what those connections can reach;
- the rules you are already bound by, from your own contracts, your sector or your customers;
- where data may be stored and processed, and where it may not.
A provider cannot design around constraints you have not written down. This list also belongs in the brief; our due diligence checklist turns each line into something you can verify before signing.
Access control is most of the work
Role-based access control and multi-factor authentication for admin dashboards are the baseline, and Netbase works that way. The practices that decide whether it holds up are more mundane:
- access granted to named individuals, never to shared accounts;
- the smallest set of permissions each role needs to do its job, reviewed when the role changes;
- your environments accessed through your own identity system where you have one;
- a written list of who has access to what, produced on request rather than reconstructed later;
- removal on the day someone leaves the project, not at the end of the engagement.
Ask a provider to show you the current access list for a project it already runs, with client details removed. The ones who manage access properly can produce it in a few minutes.
Secure development practices
Secure code review and version control are standard practice on Netbase projects. In evaluating any provider, look for the surrounding habits: every change reviewed by someone other than its author, a dependency inventory kept current, secrets held in a secret store rather than in the repository or a configuration file, and separate environments where a mistake in testing cannot reach production data.
Ask how security defects are handled when they are found late. The honest answer describes a triage route and a fix window, not a promise that they do not occur. The project delivery page explains how we fit that into milestones and acceptance.
Who can hold access, and where the data sits
Netbase delivers remote-first, and a project team may combine Netbase staff, approved specialists or disclosed partners, with Netbase remaining accountable for the result and for the people it puts on a project. Contributors work under NDA. You contract with one party: Netbase JSC, whose head office is in Hanoi, Vietnam and is the company's only office. There is no second entity to contract with, and no local office to assume.
Because the delivery network is sourced globally, the composition of the team is something to record rather than infer. Require in writing:
- the named people who may hold access to your systems, and the role each one holds;
- which of them are Netbase staff, approved specialists or disclosed partners;
- the locations from which they may connect;
- where your data is stored and processed, and which contributors may reach it;
- that any change to that list reaches you before it takes effect, not after.
Data location is a separate question from team location. Work can often happen inside your own cloud accounts and repositories, with access granted per role, so the data never leaves the environment you control and your own logging sees every session. Where that is not possible, agree explicitly where data is stored and processed and write it into the contract. The global delivery page describes how our teams are composed across locations.
AI tools and your data
Netbase uses AI-assisted engineering under human review. Any provider using these tools should tell you which ones, what they are allowed to process, whether your code or data leaves your environment to reach them, and who reviews the output before it is merged. If you need a restriction, write it into the project definition. Our AI workflow automation service page describes how we handle this when the automation itself is the deliverable.
Agree the incident route before you need it
Settle these while nothing is wrong:
- who to contact on each side, by name, and through which channel;
- how quickly the provider must tell you about a suspected breach, and what "suspected" means;
- who may take a system offline, and who decides when it comes back;
- what is logged, for how long, and who can read the logs;
- how a post-incident review is written and shared.
Distance makes the timing harder, not the process. A delivery team spread across time zones and a buyer in Berlin or Chicago need an agreed out-of-hours contact rather than an assumption; the guide to working across time zones covers how to set that up.
Questions to put to any provider
-
Access
Who will have access to which of our systems, and how is that list maintained and reviewed?
-
Authentication
Is multi-factor authentication enforced for administrative access, and to which tools?
-
Code review
Who reviews each change, and can a change reach production without a second pair of eyes?
-
Secrets
Where are credentials and keys stored, and who can read them?
-
Data
Does the team need production data, and if so, in which environments and under what controls?
-
Location
Where is our data stored and processed, and which contributors can reach it from where?
-
People
Are all contributors under NDA, including any subcontractor, and can we see the list?
-
Paperwork
Will you sign our NDA and data processing agreement, or do you offer your own?
-
Incidents
How and how quickly are we told, and who is the named contact out of hours?
-
Exit
What happens to our data, credentials and copies when the engagement ends?
The screening framework in how to compare software outsourcing companies uses the same questions across a shortlist, so the answers are comparable.
Warning signs
- Certification logos on a website with no scope, issuer or date behind them.
- Shared logins for administrative tools, described as convenient.
- Production data routinely copied into development environments.
- Subcontractors who appear in delivery but not in the contract.
- No written answer to any of the questions above, only reassurance on a call.
Ending the engagement safely
An exit is a security event. Access should be revoked the same week, not the same quarter. Agree in advance what happens to copies of your data and code, which credentials are rotated and by whom, and who confirms in writing that the provider retains nothing it should not. The guide to handover and exit covers the full sequence, and who owns the code covers the ownership side of the same handover.
Plan the next step for your project
Common questions
NDAs and data processing agreements are available on request, and we will review yours. Contributors on a project work under NDA regardless.
Often, yes. Access can be granted per role inside your accounts and repositories, which keeps data where you already control and monitor it. The arrangement is agreed in discovery and written into the contract.
No certification is claimed on this site. We describe the practices listed above, we answer security questionnaires in writing, and we tell you plainly when something you are asking for is outside what we can evidence.
Where Netbase fits
Security decisions are made early: our delivery lifecycle starts with discovery and strategic alignment, and that is where access, data location and environment rules are settled rather than discovered during build. Which engagement model you choose changes who holds administrative control day to day, so decide that in the same conversation. For how we source and review the statements on this site, see our methodology. If you want to put the questions above to us before sharing anything sensitive, contact us first.
Send us your security requirements with the brief
Submit a project and include your access, data and jurisdiction constraints; we would rather tell you early if something is outside what we can meet. OutsourcingVN is operated by Netbase JSC and is Netbase's own outsourcing-services platform.