Trust

    Security & Privacy Practices

    This page describes, in plain terms, how we handle the information clients share with us. It is written and maintained by Alloy1Consultants.

    Certification roadmap

    Alloy1Consultants is working toward ISO 27001, SOC 2, and HIPAA readiness. These are independent audits and signed agreements rather than software settings, so until they are complete we describe our practices here instead of displaying certification badges.

    We do not ask for, receive, or store protected health information today. If your project involves regulated data, tell us before we begin so we can scope the engagement appropriately or refer you to an audited provider.

    What these standards mean for your project

    Compliance is not a sticker on a website. Each framework changes how we manage risk, handle data, and demonstrate that our controls work. Here is what that looks like in practical terms once we complete the work.

    ISO 27001

    An information security management system that treats security as an ongoing program, not a one-time setup.

    For you, this means risk assessments before new tools are adopted, documented access rules, regular reviews, and a defined incident response process if something goes wrong.

    SOC 2

    An independent audit of how we protect client data across security, availability, processing integrity, confidentiality, and privacy.

    For you, this means an outside firm has tested our controls and confirmed they operate as described over a period of time, not just on the day of inspection.

    HIPAA

    The set of safeguards required when a service provider touches protected health information in the United States.

    For you, this means access controls, audit logs, encrypted transmission and storage, a signed Business Associate Agreement, and limits on who can view patient or client health records.

    What we do today

    Encryption in transit

    This website is served over HTTPS. Form submissions and account requests travel to our hosted backend over encrypted connections.

    Least privilege access

    Client data stored by this site is protected by row level access rules, so records are readable only by the account they belong to and by administrators who need them.

    Data minimization

    We collect the name, email, phone, and project details you choose to send us. Card details are handled entirely by our payment processor and never stored on our systems.

    Email and marketing choice

    Every marketing email includes an unsubscribe link, and suppression requests are honored automatically.

    Reporting a security concern

    If you believe you have found a vulnerability in this website, email info@alloy1consultants.com with steps to reproduce it. Please give us a reasonable window to respond before sharing details publicly. You can also reach us at (470) 305-2944 or through our contact page.

    We do not currently run a paid bug bounty program.