Security Statement
Practical security practices, described accurately, without compliance claims we haven't earned.
This document is provided as a working template for CloudDreamers and should be reviewed by qualified counsel before publication.
Transport and hosting
Sites we deliver are served over HTTPS with modern TLS. Hosting platforms are chosen for managed patching, isolation, and availability characteristics.
Access control
We work on a least-privilege basis. Access to client environments is limited to the people who need it, and is revoked when an engagement ends or a team member changes roles.
Payments
Card payments are handled entirely by a PCI-compliant payment processor. CloudDreamers does not store card numbers on its servers.
Client data
Lead and form data is stored securely and is not exposed client-side. Sensitive credentials are stored in secret management rather than in code or documents.
Monitoring
Managed plans include uptime and security monitoring, patching cadence, backups, and defined response expectations documented in your agreement.
What we do not claim
We do not hold out any certification, audit outcome, or regulatory compliance status unless it has been independently verified and is explicitly named. Security reviews we perform are advisory and are not a certification.
Responsible disclosure
If you believe you've found a vulnerability in this site or in something we built, contact us with the details. We'll acknowledge the report and work on a fix.
Questions about this policy? CloudDreamers, Seattle, Washington.
