Security
Last updated: 4 August 2026
We work with clients' financial and infrastructure data, so we treat access with care. Our model is simple: observe and recommend by default, and change nothing without your explicit sign-off.
How we access client systems
- Read-only by default. We use scoped, least-privilege credentials and ask only for the access an engagement actually needs.
- Temporary write access, revoked after. Where a change requires write access, we use temporary credentials that are removed as soon as the work is done.
- We work in your account. Analysis happens live in your environment. We do not export or retain your data.
- You approve every change. No destructive action is taken without your explicit go-ahead, and changes are made reversible (snapshots, deregister-before-delete, staged rollout).
- NDA on request. We are happy to sign a mutual non-disclosure agreement before an engagement.
Website security
This site is served over HTTPS through reputable hosting (Vercel) with Cloudflare providing DNS and network protection. We collect as little information as possible - see our privacy policy for what we hold and why.
Reporting a vulnerability
If you believe you have found a security issue in this website or our systems, please tell us through the contact form and include enough detail for us to reproduce it. We will acknowledge your report and work with you on a fix. We ask that you give us a reasonable chance to resolve the issue before disclosing it publicly, and we will not pursue action against good-faith researchers who follow this process.
Questions
For anything security-related, reach us through the contact form.