Security and trust

Clear boundaries for inquiries, assessments, and evidence.

We use practical safeguards to protect website inquiries and handle assessment work within agreed access, data-handling, and testing boundaries.

Customer commitments

Security work starts with control over the work.

The service agreement turns access, scope, evidence handling, contacts, stop conditions, reporting, retention, and deletion into explicit responsibilities.

PERMISSION

Written scope before testing

A contact form or public record never grants testing authority. Active work begins only after the organization and AlomSec agree the systems, methods, timing, and limits.

ACCESS

Use the minimum access required

Assessment access is limited to the approved task and period. Credentials and sensitive customer material are not requested through the public contact form.

EVIDENCE

Handle findings as customer information

Reports, technical evidence, customer context, and access terms are governed by the engagement agreement, including who may receive them and how long they are retained.

OPERATIONS

Respect business constraints

Request rates, maintenance windows, fragile systems, escalation contacts, stop conditions, and prohibited techniques are defined for the environment.

DELIVERY

Separate facts from assumptions

Reports distinguish confirmed findings, observations, limitations, and unreviewed areas so missing coverage does not become false confidence.

CLOSURE

Define what counts as fixed

Retesting checks the original condition against an agreed closure requirement and records any remaining or changed risk.

Public website

Collect less and expose less.

The marketing site is limited to public information and a protected inquiry form. Customer workspaces are isolated on the separate portal service; assessment systems and customer records are not exposed through this site.

Encrypted delivery

The public site and form use HTTPS. Security headers restrict browser behavior and third-party content.

No advertising tracking

AlomSec does not add advertising pixels, behavioral profiling, or audience-measurement cookies.

Protected form

Abuse checks, request limits, strict fields, and restricted delivery reduce automated misuse and prevent arbitrary mail routing.

Minimal inquiry data

The form asks for business contact and scoping information. It does not accept files, passwords, patient data, or client records.

Bounded contact intake

The contact service accepts an exact, size-limited form contract, validates a single-use challenge, and can deliver only to the fixed private mailbox.

Read the privacy notice.

Customer service controls

Facts a buyer can verify before engagement.

These controls describe the current service boundary. They are not a certification, warranty, or claim that every customer environment is covered automatically.

IDENTITY

MFA-required customer access

New portal tenants require TOTP by default. Reused codes are rejected, browser sessions can be reviewed and revoked, and password changes revoke other sessions.

ISOLATION

Tenant and client scope

Customer data reads carry tenant and client identity. Partner users receive all-client access only when explicitly granted; white-label domains map to one verified tenant.

INTEGRITY

Evidence-bound reporting

All 20 rubric observations require a published anchor, written rationale, and bound evidence references. Publication is refused when the derivation, evidence revision, payment gate, or assessment fingerprint changes.

RECOVERY

Verified, revision-bound backups

Portal backups use an online SQLite snapshot, bind the release and schema, inventory every file, and refuse plaintext secrets. Restore is a separate verified operator action.

DELIVERY

Restricted public surface

The marketing origin and customer portal bind to loopback behind an outbound tunnel. Static site bytes are checked against a complete SHA-256 manifest before the origin listens.

LIMITS

No invented operating claims

Argus Watch is scheduled assurance, not a 24/7 SOC or MDR service. AlomSec does not claim a certification, insurance coverage, or independent attestation it cannot document.

01

Statement of work and rules of engagement

Names the organization, systems, access, techniques, dates, request limits, exclusions, escalation contacts, stop conditions, deliverables, and fee.

02

Confidentiality and data handling

Defines permitted evidence, recipients, storage boundary, retention, deletion, incident notification, and any customer-specific handling constraints.

03

Privacy and provider terms

Where the work requires processing personal information, the parties can document roles, required data terms, and the provider categories used for the agreed service.

04

Control evidence

Buyers may request the current architecture, security boundaries, backup and recovery contract, testing evidence, and stated residual risks relevant to their engagement.

01

Evidence-bound cleanup

Automatic changes are restricted to confirmed campaign indicators. Unfamiliar remote-management software is reported for review instead of being deleted blindly.

02

Static download surface

The public origin accepts GET and HEAD only, serves an exact route allowlist, and verifies every published byte before listening.

03

No incident uploads

Do not send patient records, client records, mailbox exports, credentials, or forensic evidence through the public website.

01

Good-faith reports

We review reproducible reports concerning AlomSec's owned public services and reply through the work email supplied in the form.

02

Protect people and availability

Do not access another person's data, disrupt service, use social engineering, persist after proof, or publish sensitive evidence before coordinated review.

03

Reporting is not blanket authorization

The reporting channel permits responsible communication. It does not authorize active testing beyond ordinary good-faith observation without written permission.