Security & Data Practices
Last updated: 20 July 2026
This page describes, honestly, how we approach the security of your information. We would rather under-promise here than claim protections we cannot yet prove.
Data minimization
We collect only the information needed to respond to you and to scope a possible engagement. We do not ask for sensitive data through this website.
The first review needs no production access
Our initial workflow review is a conversation and a mapping exercise. It does not require access to your live systems, credentials, or customer data.
Access only when a project requires it
If an engagement proceeds, any access to your tools or data is defined in a written agreement, limited to what the work requires, and removed when it is no longer needed.
No selling of data
We do not sell or rent your information. See our Privacy Policy for how form submissions are handled.
What we do not claim
We do not currently claim formal certifications such as SOC 2 or ISO 27001. If we obtain independently verified certifications or controls in the future, we will state them here — and only then.
Reporting a concern
If you have a security question or want to report a concern, email [email protected].