A bank, insurer, or hospital should require a partner that can show how its systems enforce the rules, not one that only promises to comply. In practice that means sensitive data kept out of marketing tools by design, access controls with MFA and audit trails, security that works under a strict Content Security Policy, and code and data that stay under your control.
Andes Development earned its stripes building and operating banking infrastructure. This is the list of questions we wish every regulated client would ask any vendor, including us.
Why isn't "we're compliant" enough?
Because a disclaimer doesn't stop a data leak. Architecture that makes the mistake impossible does.
The useful question isn't "are you compliant?" It's "how does the system make it impossible not to be?" If the answer is a policy PDF instead of a technical explanation, keep looking.
What should you ask about sensitive data?
Where does each piece of data go? For a bilingual insurance agency in Central Texas, we built forms that work as a filter, not a mirror: health and financial-account answers stay in a secure vault, and only the fields sales needs ever reach the CRM. TCPA-compliant consent is captured at the source. Read the case.
How do you measure ads without surveillance? That same project runs no Google Analytics and no session recording. The ad click identifier follows the lead and is reported to Google as an offline conversion only once the lead is qualified.
Who sees what? Ask about roles, per-model permissions, and an audit trail of who changed what.
What security controls should a banking project include?
These are the controls we built into a self-service platform for a regional financial institution, delivered in six weeks:
- An admin panel restricted by IP and ranges, with MFA and passkeys.
- reCAPTCHA against brute-force attacks.
- Authentication encryption aligned with the financial group's corporate standards.
- A Content Security Policy with nonces and
unsafe-inlinemitigated, to pass the bank's security evaluations. - Telemetry for every step of the flow.
On a branch locator for a national bank we went further: a separate CSP for each surface, embedded maps gated by a signed token and a domain allowlist, and API keys that are scoped, IP- and domain-restricted, and stored hashed. Read the case.
Can marketing tools be secure too?
They have to be, and it's where most teams cut corners. Many commercial cookie banners require unsafe-inline or eval, exactly what a strict CSP forbids: the script meant to protect privacy ends up weakening the site's security.
That's why we built Andes Consent: a 15 KB consent script with zero dependencies that runs under a strict CSP and Trusted Types, supports Google Consent Mode v2, and ships with 245 automated tests. It covers eight legal frameworks, including GDPR, CCPA/CPRA, and the Texas privacy act. Its first production deployment is a healthcare site.
You can also measure without tracking: the bank's locator uses cookieless analytics that discard the IP address.
What about HIPAA, TCPA, and Texas insurance rules?
For the insurance agency, three rules shaped the design: Texas insurance-privacy rules require an opt-in before health information is disclosed, Google prohibits receiving sensitive health data, and TCPA governs every follow-up call and text. Each one maps to a specific part of the system: the secure form vault, the offline conversion setup, and consent captured at the source.
An honest caveat: we're engineers, not lawyers. Ask your compliance team for the current requirements and expect your vendor to meet them with architecture, not promises.
A checklist for your next vendor
| Requirement | Question | A good answer sounds like |
|---|---|---|
| Sensitive data | What data reaches the CRM and the ad platform? | "Only these fields; the rest stays in a separate vault." |
| Access | How does an administrator sign in? | "With MFA or passkeys, from approved IPs, with an audit trail." |
| Web security | Does the site run under a strict CSP? | "Yes, with nonces and no unsafe-inline." |
| Consent | Do scripts run before the visitor agrees? | "No, they're blocked until consent is given." |
| Ownership | Who owns the code and the cloud account? | "You do, from day one." |
| Continuity | What happens if the person on my project leaves? | "Everything is documented and your team is already trained." |
Who owns the code and the data?
You do. On our projects the code lives in your repositories and the infrastructure in your account. For the insurance agency we also delivered a private training site that walks the team through the system stage by stage, so they operate it with confidence. It's the same rule we recommend when evaluating a nearshore team.
Do you work in a regulated industry?
We know the operation from the inside: banking cores, hospital uptime, and the visibility rules of international funders. See how we work with banks or with healthcare organizations. And if your infrastructure needs hardening, see cloud infrastructure and cybersecurity.
Sources
- Andes Development case studies cited in the text.