Privacy & Terms

Plain-language privacy and engagement terms.

What I collect when you contact me, how it's used, and the ground rules for any business launch, website, product, platform, or application security work. No dark patterns, no data resale.

Privacy

What I collect and why

Guided contact & self-check

The guided contact intake and readiness self-check run in your browser. I receive only the information you choose to include after opening and sending an email draft, such as your name, email, phone, company, product, timing, message, or self-check result.

How it's used

To respond to you, prepare a recommendation and quote, and keep a record of our conversation. I don't sell your data, share it with advertisers, or add you to marketing lists without your say-so.

How messages are delivered

The current intake prepares an email draft on your device. Nothing is submitted automatically through the website. The site itself is served over HTTPS through Cloudflare.

Retention & your choices

I keep inquiry records only as long as useful for our working relationship. Email [email protected] any time to ask what I hold, correct it, or have it deleted.

Security engagements

Rules of engagement for application security testing

Security testing is performed only with written authorization, a defined scope, explicit testing boundaries, and documented handling of findings.

Written authorization first

No testing happens until scope, targets, and authorization are confirmed in writing. Testing is limited strictly to systems you own or are authorized to assess.

Mutual NDA

Findings, access details, and your business information are treated as confidential and can be covered by a mutual non-disclosure agreement.

Written findings

You receive clear findings: plain-language consequence for leadership, reproducible technical detail for implementers, and prioritized remediation guidance—with retest validation when included in the agreed scope.

Questions about any of this?

Email me directly and I'll answer plainly.