Loading…
Loading…
How this practice accesses client systems, what data it touches, which third parties process it, and what is deliberately not claimed.
Last reviewed
This page exists so that a security review does not need a meeting. Everything below is either a statement of practice that an engagement is contractually held to, or a control implemented in code you can read — the site you are on is open about its own infrastructure, and the controls listed further down name the file that implements them.
If your process needs a completed questionnaire, ask and one comes back inside two business days. The preferred instrument is VSA-Core, which is explicitly sized to the vendor's actual role; a full SIG Core sent to a single contractor with no standing access to your systems is a few hundred hours of mismatch on both sides, and it is reasonable to say so before starting one.
There is no SOC 2 report and no ISO 27001 certificate. That is a deliberate position, not an oversight: a one-person practice cannot satisfy segregation-of-duties controls without inventing a second person, and buying an attestation speculatively is a poor trade at this size. What replaces it is the rest of this page — a narrow, written access model, a subprocessor list specific enough to answer questionnaire items directly, and controls you can verify by reading the source rather than by trusting a summary.
If an attestation is a hard requirement for a specific engagement, say so early. It is answerable, it takes weeks rather than days, and it is much better raised before a statement of work than after one.
There has been no security incident affecting client data. If one occurs, you will hear it from me directly and within 72 hours of my becoming aware, with what happened, what was affected, and what changed as a result — before it is comfortable to send, not after.
Separate from any client engagement, this website stores what visitors submit to it: inquiry name, email, subject and message body; booking name, email and session time; and a non-reversible fingerprint of the request IP used only to deduplicate submissions. Card details are entered directly into Stripe-hosted frames and are never seen by this site or stored in its database. To have any of it deleted, write to the contact address and it is removed rather than flagged.
How much of your estate this engagement actually touches. Vendor-risk tiering keys off integration depth and privileged access rather than contract value, so this section — not the size of the invoice — is what determines how deep a review needs to go.
Every third party that can see data passing through this site, what it does, and what it can see. This list is exhaustive as of the review date at the top of this page; a new subprocessor is added here before it is added to the system.
| Subprocessor | Purpose | Data it can see | Processing location |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, edge compute (Workers), database (D1), cache (KV), object storage (R2), bot mitigation (Turnstile), request analytics, and the Workers AI model used to categorise inbound messages. | Everything submitted through the site: name, email, message body, booking times, and a non-reversible fingerprint of the request IP. | Global edge network; data at rest in Cloudflare D1 and R2. |
| Stripe, Inc. | Card verification for session bookings and card payments for paid work. Card details are entered into Stripe-hosted iframes and are never seen by this site. | Name, email, payment card data, payment amounts. | United States and Stripe global infrastructure. |
| Cal.com, Inc. | Calendar event creation, rescheduling and cancellation for booked sessions. | Name, email, and the session date and time. | United States / EU, per Cal.com configuration. |
| Telegram Messenger | Operator notification only — a new inquiry or booking pages the developer. No client data is stored in Telegram beyond the notification message itself. | Name, email, subject and message body of an inbound inquiry. | Telegram global infrastructure. |
Asserted controls are worth what the reader's trust in the asserter is worth. These name the file that implements them, in a repository that is the same codebase serving this page.
| Control | What it does | Implemented in |
|---|---|---|
| Constant-time secret comparison | Shared secrets and bearer tokens are compared byte-by-byte in constant time, so a timing side channel cannot be used to recover them one character at a time. | apps/web/src/lib/secrets.ts |
| Capability tokens with no enumeration oracle | Booking management links and payment links are 256-bit random tokens. There is deliberately no lookup by name, email or reference, so holding one token reveals nothing about any other record. | apps/web/src/lib/booking-manage.ts, apps/web/src/lib/payment-slip.ts |
| Signed-webhook verification | Inbound Stripe webhooks are verified against the signing secret before any state change. An unsigned or replayed payload is rejected. | apps/web/src/app/api/webhooks/stripe/route.ts |
| Rate limiting on every open write endpoint | Any unauthenticated POST that can reach Stripe, Workers AI or a database write is capped per-IP in a KV window. | apps/web/src/lib/rate-limit.ts |
| Bot mitigation on public forms | Cloudflare Turnstile is verified server-side before an inquiry is accepted. | apps/web/src/lib/turnstile.ts |
| No raw IP addresses retained | Request IPs are reduced to a non-reversible fingerprint used only for deduplication; the address itself is never written to the database. | apps/web/src/lib/contact-intake.ts |
| Generic error responses | Server errors are logged in full and returned to callers as a generic message, so an exception cannot leak internal structure to an anonymous request. | apps/web/src/lib/http.ts |
| Append-only financial ledger | Every payment lifecycle event is written to an append-only ledger table with a foreign key to its subject, so the audit trail cannot be orphaned by deleting the record it describes. | apps/web/migrations/0011_payment_slips.sql |
| Agent surface is contract-tested | The MCP tool manifest published to AI agents is asserted in CI against the tools actually registered. A capability cannot ship undeclared, and a declared capability cannot silently disappear. | apps/worker/src/lib/__tests__/config-contract.test.ts |
Stated rather than omitted. A reviewer who has to discover an absence reads it as something that was being hidden; a reviewer who is told about it up front spends the time on the compensating controls instead.
No SOC 2 or ISO 27001. The compensating controls are the access model and the control list above.
Sized to the vendor's actual role. A longer instrument is answerable, but it is worth agreeing on proportionality before starting one.
From receipt of the completed form, not from the first email in the thread.
The objection in its strongest form is that hiring one external person instead of depending on one internal person relocates the risk rather than removing it. That is a fair objection and it deserves a specific answer rather than a reassurance.
The answer is on the vendor & procurement page, alongside the contracting model it belongs to.
Send the question rather than the whole questionnaire first — most of what a review needs is on this page, and the remainder is usually two or three specifics. Written questions get a reply within 4 hours; a completed questionnaire comes back separately, on its own timeline.
Ask a procurement question