Privacy & Terms

Plain-language privacy and engagement terms.

What I collect when you contact me, how it's used, and the ground rules for any website or security work. No dark patterns, no data resale.

Privacy

What I collect and why

Contact form & risk check

When you use the contact form or website risk check, I receive the information you choose to enter, such as your name, email, phone, company, website, timing, message, or risk-check result. I use it only to reply and understand the work.

How it's used

To respond to you, prepare a recommendation and quote, and keep a record of our conversation. I don't sell your data, share it with advertisers, or add you to marketing lists without your say-so.

How messages are delivered

The current form prepares an email draft on your device. If secure form delivery is enabled later, submissions may pass through Web3Forms solely to deliver the message to me. The site itself is served over HTTPS through Cloudflare.

Retention & your choices

I keep inquiry records only as long as useful for our working relationship. Email [email protected] any time to ask what I hold, correct it, or have it deleted.

Security Engagements

Rules of engagement for security & pen testing

Security testing is performed only with written authorization, a defined scope, explicit testing boundaries, and documented handling of findings.

Written authorization first

No testing happens until scope, targets, and authorization are confirmed in writing. Testing is limited strictly to systems you own or are authorized to assess.

Mutual NDA

Findings, access details, and your business information are treated as confidential and can be covered by a mutual non-disclosure agreement.

Written findings

You receive a clear report: plain-language risk for leadership, reproducible technical detail for your implementers, and prioritized fixes - with retest support to validate remediation.

Questions about any of this?

Email me directly and I'll answer plainly.