Trust
Security & Privacy Practices
This page describes, in plain terms, how we handle the information clients share with us. It is written and maintained by Alloy1Consultants.
Certification roadmap
Alloy1Consultants is working toward ISO 27001, SOC 2, and HIPAA readiness. These are independent audits and signed agreements rather than software settings, so until they are complete we describe our practices here instead of displaying certification badges.
We do not ask for, receive, or store protected health information today. If your project involves regulated data, tell us before we begin so we can scope the engagement appropriately or refer you to an audited provider.
What these standards mean for your project
Compliance is not a sticker on a website. Each framework changes how we manage risk, handle data, and demonstrate that our controls work. Here is what that looks like in practical terms once we complete the work.
ISO 27001
An information security management system that treats security as an ongoing program, not a one-time setup.
For you, this means risk assessments before new tools are adopted, documented access rules, regular reviews, and a defined incident response process if something goes wrong.
SOC 2
An independent audit of how we protect client data across security, availability, processing integrity, confidentiality, and privacy.
For you, this means an outside firm has tested our controls and confirmed they operate as described over a period of time, not just on the day of inspection.
HIPAA
The set of safeguards required when a service provider touches protected health information in the United States.
For you, this means access controls, audit logs, encrypted transmission and storage, a signed Business Associate Agreement, and limits on who can view patient or client health records.
What we do today
Encryption in transit
This website is served over HTTPS. Form submissions and account requests travel to our hosted backend over encrypted connections.
Least privilege access
Client data stored by this site is protected by row level access rules, so records are readable only by the account they belong to and by administrators who need them.
Data minimization
We collect the name, email, phone, and project details you choose to send us. Card details are handled entirely by our payment processor and never stored on our systems.
Email and marketing choice
Every marketing email includes an unsubscribe link, and suppression requests are honored automatically.
Reporting a security concern
If you believe you have found a vulnerability in this website, email info@alloy1consultants.com with steps to reproduce it. Please give us a reasonable window to respond before sharing details publicly. You can also reach us at (470) 305-2944 or through our contact page.
We do not currently run a paid bug bounty program.
Keep exploring
Related services, pricing, and guides so you can compare options in one pass.