Our policies

Security and data practices.

Simple principles guide how we protect information, manage access, address risk, and dispose of records responsibly.

Effective July 13, 2026 · Owned by company leadership · Reviewed at least annually

Information security

We maintain a written security program that applies to our people, service providers, company devices, and production services. It is reviewed at least annually and whenever a material change or incident calls for an update.

  • Encrypted connections are required for public services.
  • Sensitive information is kept out of public files and source history.
  • Security activity is monitored and important findings are tracked to completion.
  • Backups are made before material production changes.

Access control

Access is limited to the people and services that need it. Administrative access is separated from ordinary use wherever practical.

  • Critical financial services use multi-factor authentication.
  • Production access uses encrypted connections and individual credentials.
  • Privileged access is reviewed every quarter.
  • Access is changed promptly when responsibilities change and removed when it is no longer needed.
  • Automated services receive only the permissions required for their purpose.

Risk, updates, and supported software

Automated checks review our public website, security settings, software advisories, and file access every week. Important findings are brought to company leadership for review.

Our target is to address critical and important issues within seven days, high-risk issues within 30 days, and moderate issues within 90 days. We review the support life of software and upgrade, replace, or isolate it before support ends.

Incident response

Suspected incidents are reported to company leadership immediately. We confirm the scope, contain access, preserve relevant records, correct the cause, restore services carefully, and document what should change. We notify affected providers and individuals when required by law or contract.

Retention and disposal

We keep information only as long as it serves a clear business, security, or legal purpose.

  • Contact inquiries: up to 12 months after resolution.
  • Security records: generally 90 days to one year.
  • Policy, review, and incident records: three years.
  • Transaction, accounting, and tax records: up to seven years when required.

At the end of the relevant period, electronic information is deleted through provider controls, secure deletion, or removal of the keys that protect it. Paper records are securely destroyed. A legal hold may pause routine deletion for specific records.

Questions and requests

Use the contact form for a security question, a privacy request, or to report a concern. Please do not include passwords, account numbers, or other sensitive details in the message.