← Back home

Security

Current safeguards and the controls required before production data collection.

Data handling

The AI audit limits collection to assessment responses, business contact details, consent, and attribution. Production submissions require private server-side storage; if storage is unavailable, the service does not retain contact details.

Encryption

The production site is intended to run over HTTPS, and the application sends an HSTS policy on HTTPS responses. Hosting and processor encryption controls are reviewed as part of production configuration.

Access control

Audit data is available only to server code through private environment bindings. There is no public report lookup or administrative data route. An internal interface will remain disabled until an approved authentication and authorization mechanism is configured.

Vendor due diligence

Optional hosting, scheduling, analytics, CRM, webhook, email, and AI providers are enabled only after their purpose, data access, credentials, and contractual controls are reviewed. A provider is not treated as approved merely because configuration fields exist.

AI tooling guidelines

Audit scores and recommendations are deterministic. The active narrative path is also deterministic; no third-party AI provider is enabled by default. Any future provider must pass privacy, data-minimization, structured-output, and safety review.

Incident response

If we become aware of a security incident affecting client data, we will notify the affected client without undue delay and cooperate on remediation.

Report a concern

Found a vulnerability or have a security question? Email hello@commondenominator.email and we'll respond promptly.