WriteChoice

Secure Development Policy

WriteChoice delivers documentation, not production software, so its secure development lifecycle covers how documentation and code samples are written, reviewed, and published without exposing client secrets or systems.

Version 1.0 Effective September 2026 Owner Security Officer (COO) Review At least once a year Contact security@writechoice.io

3.1 Where work happens

  • Documentation is managed as code, in the client's repository whenever the client provides one, or in a private WriteChoice GitHub repository otherwise.
  • Repositories holding client material are private; access follows the Access Control Policy.
  • Personnel work only in documentation repositories and sandbox or test environments. WriteChoice never requires access to production systems.

3.2 Change process

  1. Every change is made on a separate branch.
  2. Changes are submitted as a pull request with a description of what changed.
  3. A second person reviews the pull request for accuracy, sensitive information, and code sample safety before merge, unless the client's own review process replaces this step.
  4. Publishing follows the client's release process; WriteChoice does not bypass the client's approvals.

3.3 Secrets and sensitive data

  • No real credentials, API keys, tokens, customer data, or internal hostnames are committed to repositories or placed in documentation.
  • Code samples use placeholder values (for example YOUR_API_KEY) and sandbox or test data only.
  • Sandbox credentials received from a client are stored in the password manager.
  • If a secret is committed by mistake, it is treated as a security incident: the client is told so the secret can be rotated, and the commit is removed from history where possible.

3.4 Code samples

  • Code samples follow the client's published security guidance (for example HTTPS only, no disabled certificate checks, no hard-coded secrets).
  • Samples are tested against sandbox environments before publication when the client provides one.

3.5 Tooling

  • Two-factor authentication is enforced on GitHub.
  • Branch protection and required reviews are used on WriteChoice-owned repositories that hold client material.