Written scope before testing
A contact form or public record never grants testing authority. Active work begins only after the organization and AlomSec agree the systems, methods, timing, and limits.
Security and trust
We use practical safeguards to protect website inquiries and handle assessment work within agreed access, data-handling, and testing boundaries.
Customer commitments
The service agreement turns access, scope, evidence handling, contacts, stop conditions, reporting, retention, and deletion into explicit responsibilities.
A contact form or public record never grants testing authority. Active work begins only after the organization and AlomSec agree the systems, methods, timing, and limits.
Assessment access is limited to the approved task and period. Credentials and sensitive customer material are not requested through the public contact form.
Reports, technical evidence, customer context, and access terms are governed by the engagement agreement, including who may receive them and how long they are retained.
Request rates, maintenance windows, fragile systems, escalation contacts, stop conditions, and prohibited techniques are defined for the environment.
Reports distinguish confirmed findings, observations, limitations, and unreviewed areas so missing coverage does not become false confidence.
Retesting checks the original condition against an agreed closure requirement and records any remaining or changed risk.
Public website
The marketing site is limited to public information and a protected inquiry form. Customer workspaces are isolated on the separate portal service; assessment systems and customer records are not exposed through this site.
The public site and form use HTTPS. Security headers restrict browser behavior and third-party content.
AlomSec does not add advertising pixels, behavioral profiling, or audience-measurement cookies.
Abuse checks, request limits, strict fields, and restricted delivery reduce automated misuse and prevent arbitrary mail routing.
The form asks for business contact and scoping information. It does not accept files, passwords, patient data, or client records.
The contact service accepts an exact, size-limited form contract, validates a single-use challenge, and can deliver only to the fixed private mailbox.
Customer service controls
These controls describe the current service boundary. They are not a certification, warranty, or claim that every customer environment is covered automatically.
New portal tenants require TOTP by default. Reused codes are rejected, browser sessions can be reviewed and revoked, and password changes revoke other sessions.
Customer data reads carry tenant and client identity. Partner users receive all-client access only when explicitly granted; white-label domains map to one verified tenant.
All 20 rubric observations require a published anchor, written rationale, and bound evidence references. Publication is refused when the derivation, evidence revision, payment gate, or assessment fingerprint changes.
Portal backups use an online SQLite snapshot, bind the release and schema, inventory every file, and refuse plaintext secrets. Restore is a separate verified operator action.
The marketing origin and customer portal bind to loopback behind an outbound tunnel. Static site bytes are checked against a complete SHA-256 manifest before the origin listens.
Argus Watch is scheduled assurance, not a 24/7 SOC or MDR service. AlomSec does not claim a certification, insurance coverage, or independent attestation it cannot document.
Names the organization, systems, access, techniques, dates, request limits, exclusions, escalation contacts, stop conditions, deliverables, and fee.
Defines permitted evidence, recipients, storage boundary, retention, deletion, incident notification, and any customer-specific handling constraints.
Where the work requires processing personal information, the parties can document roles, required data terms, and the provider categories used for the agreed service.
Buyers may request the current architecture, security boundaries, backup and recovery contract, testing evidence, and stated residual risks relevant to their engagement.
Automatic changes are restricted to confirmed campaign indicators. Unfamiliar remote-management software is reported for review instead of being deleted blindly.
The public origin accepts GET and HEAD only, serves an exact route allowlist, and verifies every published byte before listening.
Do not send patient records, client records, mailbox exports, credentials, or forensic evidence through the public website.
We review reproducible reports concerning AlomSec's owned public services and reply through the work email supplied in the form.
Do not access another person's data, disrupt service, use social engineering, persist after proof, or publish sensitive evidence before coordinated review.
The reporting channel permits responsible communication. It does not authorize active testing beyond ordinary good-faith observation without written permission.