Security

Reporting a vulnerability

Email security@algomason.com. We will acknowledge within two business days. Please do not disclose publicly before we have had a chance to respond.

Access and credentials

We ask for the narrowest access that lets us do the work, and we ask you to revoke it at the end of the engagement. Credentials are never committed to version control or shared over email or chat. Where you offer production access we do not need, we will decline it.

Client data

We prefer to work against synthetic or anonymized data. Where real data is necessary, we keep only what the work requires and delete it at the end of the engagement.

Agreements

We sign your NDA. A data processing agreement is available on request. We do not currently hold SOC 2 or ISO 27001 certification, and we would rather tell you that here than during a procurement review.