do.enterprises
Trust

Posture, stated plainly.

What is true today and what is not yet in place, so a CISO can read it without a call.

What is true.

Cookies, analytics, tracking scripts noneView the source and check.
External requests from any page noneFonts are self-hosted on this site.
Where a problem brief is stored the operator’s own Cloudflare databaseThe form posts to this site’s own handler and nowhere else; no third-party form, CRM, or mailing service.
Where data lives Cloudflare’s networkPages are static files; the brief database sits in the operator’s own Cloudflare account and nowhere else.
Subprocessors CloudflareIt serves the site and stores the brief. If notification is switched on, a one-line summary of a new brief (name, role, email, the first line of the signal) posts to the operator’s own private workspace; the brief itself never leaves the database.
What intake asks for the signal categoryNever customer records; intake is designed to need no personal data about your customers.
Brief deletion on requestRemoved within ten business days, confirmed in writing.
Engagement data segregated per delivered businessOwn accounts, own domains, own data stores; nothing pooled across partners.
Statutory and consent steps licensed humansAuthorize, sign, pay, notarize; never an agent.

What is not yet in place.

SOC 2 report Not audited under SOC 2 or any comparable framework, and not claimed. When a report exists, this page will carry its date and scope.
Penetration test report None published, and none claimed.
Data-processing agreement Not published here. Papered per engagement, with the engagement letter.

Questions from a CISO or a procurement team go through the contact form; mark the brief “posture question” and a person replies in writing.

Last reviewed 2026-08-22