Privacy Policy
Effective date: August 2026. We collect only the information needed to evaluate your environment, deliver the agreed services, and maintain required business records. We do not sell or monetize your data.
What We Collect
- Name and contact info from assessments
- Assessment responses and technical details you provide
- Communication records about our services
How We Use It
- Generate your security assessment and deliverables
- Communicate findings and recommendations
- Provide ongoing advisory and monitoring
How We Protect Client Data
Client reports, configuration exports, screenshots, logs, and other technical evidence are encrypted in transit and at rest and are available only to personnel assigned to the engagement. We do not use client data to train AI models or for unrelated product development.
Access to Client Environments
When we access a client environment, we use named accounts, multi-factor authentication, and the least privilege required for the work. Reviews are read-only whenever possible. Any configuration change requiring elevated access is agreed with the client in advance, performed through an attributable account, and documented. Engagement access is removed when it is no longer required.
Retention and Deletion
Technical engagement data is deleted within 90 days after final delivery unless a different period is required by the engagement agreement, requested by the client, or required by law. We retain ordinary business records such as contracts and invoices for applicable legal and accounting periods.
Service Providers and Subprocessors
We use a limited number of service providers to operate the website and deliver services. For example, Web3Forms processes contact-form submissions, and Google may process scheduling information when online booking is enabled. These providers receive only the information needed to perform their function. We do not sell client data or share it for advertising.
Security Incidents
If we confirm a security incident affecting client data in our custody, we will notify the affected client without undue delay and, where practicable, within 72 hours. We will provide available information about the affected data, the containment actions taken, and recommended client actions.
Your Rights
You can request access, correction, return, or deletion of your data, subject to contractual and legal retention requirements. Data-processing agreements, confidentiality agreements, and business associate agreements are available when applicable to the engagement. To make a request, use our Contact page.
Data Security
We use encryption, access controls, secure storage, and documented access practices appropriate for the sensitivity of assessment and engagement data.