Posture, stated plainly.
What is true today and what is not yet in place, so a CISO can read it without a call.
What is true.
Cookies, analytics, tracking scripts
noneView the source and check.
External requests from any page
noneFonts are self-hosted on this site.
Where a problem brief is stored
the operator’s own Cloudflare databaseThe form posts to this site’s own handler and nowhere else; no third-party form, CRM, or mailing service.
Where data lives
Cloudflare’s networkPages are static files; the brief database sits in the operator’s own Cloudflare account and nowhere else.
Subprocessors
CloudflareIt serves the site and stores the brief. If notification is switched on, a one-line summary of a new brief (name, role, email, the first line of the signal) posts to the operator’s own private workspace; the brief itself never leaves the database.
What intake asks for
the signal categoryNever customer records; intake is designed to need no personal data about your customers.
Brief deletion
on requestRemoved within ten business days, confirmed in writing.
Engagement data
segregated per delivered businessOwn accounts, own domains, own data stores; nothing pooled across partners.
Statutory and consent steps
licensed humansAuthorize, sign, pay, notarize; never an agent.
What is not yet in place.
SOC 2 report
Not audited under SOC 2 or any comparable framework, and not claimed. When a report exists, this page will carry its date and scope.
Penetration test report
None published, and none claimed.
Data-processing agreement
Not published here. Papered per engagement, with the engagement letter.
Questions from a CISO or a procurement team go through the contact form; mark the brief “posture question” and a person replies in writing.
Last reviewed 2026-08-22