Security
Reporting a vulnerability
Email security@algomason.com. We will acknowledge within two business days. Please do not disclose publicly before we have had a chance to respond.
Access and credentials
We ask for the narrowest access that lets us do the work, and we ask you to revoke it at the end of the engagement. Credentials are never committed to version control or shared over email or chat. Where you offer production access we do not need, we will decline it.
Client data
We prefer to work against synthetic or anonymized data. Where real data is necessary, we keep only what the work requires and delete it at the end of the engagement.
Agreements
We sign your NDA. A data processing agreement is available on request. We do not currently hold SOC 2 or ISO 27001 certification, and we would rather tell you that here than during a procurement review.