// Trust · Security

SECURITY

This page describes, at a level that does not facilitate attacks, how we approach the security of this website and of the work we deliver. It intentionally omits providers, configurations, architecture details and control specifics.

In legal review — content pending attorney sign-off

1. Principles

  • Least privilege and separation of duties in access to systems and data.
  • Encryption of data in transit; protection of data at rest according to its classification.
  • Change review before release, with traceability of who approved what.
  • Data minimization: we collect only what a purpose requires.
  • Security considered from design, not added after delivery.

2. Operational practices

We maintain dependency review, logging appropriate to the risk, and internal procedures for handling incidents and notifying affected parties where required. [CONFIRM] Incident-response commitments, notification windows and any customer-facing SLA before stating them publicly.

We do not publish provider names, network topology, control configurations, tooling or credentials handling. Sharing that detail is done only under agreement with parties that have a legitimate need.

3. Certifications

No certification, attestation or audit result is claimed on this page. Any future certification will be published only once formally obtained and verifiable. [CONFIRM] Certification roadmap.

4. Reporting a vulnerability

If you believe you have found a vulnerability, report it privately to [PLACEHOLDER — security reporting mailbox] with enough detail to reproduce it. Please do not run tests that degrade service, access third-party data or exfiltrate information. [CONFIRM] Coordinated-disclosure policy, safe-harbour language and response times.

Questions about this document? Write to us through the contact form.

Contact