This page describes the security posture of the public website. It does not claim a certification or describe the security controls of a separate client deployment.
Public website controls
The site is static and has no user accounts, database, or server-side audit-form storage. When deployed using the included Vercel configuration, response headers restrict content sources, framing, browser permissions, and unsafe object loading. The audit form opens a message in the visitor's own mail application; it does not transmit data automatically.
Secure-by-design approach
- Use the minimum access needed for an agreed workflow.
- Keep approved business knowledge, workflow rules, and human handoff boundaries explicit.
- Apply human approval to sensitive or unsupported actions.
- Review integrations, credentials, and data handling as part of implementation scoping.
Implementation engagements
Security controls for an actual client workflow depend on the selected integrations, data types, deployment environment, access model, and contractual requirements. Those details are documented in the implementation scope rather than assumed from this marketing website.
Report a concern
To report a website security concern, email [email protected] with a clear description and safe reproduction details. Please do not include credentials or sensitive customer data.