Security
Current safeguards and the controls required before production data collection.
Data handling
The AI audit limits collection to assessment responses, business contact details, consent, and attribution. Production submissions require private server-side storage; if storage is unavailable, the service does not retain contact details.
Encryption
The production site is intended to run over HTTPS, and the application sends an HSTS policy on HTTPS responses. Hosting and processor encryption controls are reviewed as part of production configuration.
Access control
Audit data is available only to server code through private environment bindings. There is no public report lookup or administrative data route. An internal interface will remain disabled until an approved authentication and authorization mechanism is configured.
Vendor due diligence
Optional hosting, scheduling, analytics, CRM, webhook, email, and AI providers are enabled only after their purpose, data access, credentials, and contractual controls are reviewed. A provider is not treated as approved merely because configuration fields exist.
AI tooling guidelines
Audit scores and recommendations are deterministic. The active narrative path is also deterministic; no third-party AI provider is enabled by default. Any future provider must pass privacy, data-minimization, structured-output, and safety review.
Incident response
If we become aware of a security incident affecting client data, we will notify the affected client without undue delay and cooperate on remediation.
Report a concern
Found a vulnerability or have a security question? Email hello@commondenominator.email and we'll respond promptly.