Infrastructure
- Production runs in a dedicated AWS account in the United States, separate from any other business.
- All traffic is served over HTTPS with automatically renewed certificates, HSTS and a strict set of security headers.
- Admin consoles are private: not indexed, not framed, and reachable only by signed-in staff.
- Servers use least-privilege roles; instance metadata is locked to the server itself.
Data
- Secrets and API keys are stored encrypted and never written to source code; every change is scanned for leaked secrets before it can merge.
- Databases are backed up nightly, encrypted, copied off-site, and restore drills are run on a schedule.
- We keep only what a project needs. Ask and we delete it — including from our prospecting sources — and keep a record that we did.
- Payments are handled by our payment provider; card details never touch our servers.
Access to your accounts
- We work in accounts you own and add us to, so you can remove our access at any time.
- We never ask for your passwords by email or chat. You sign in yourself; we use invited or role-based access.
- At hand-over you receive every login, and we remove our own access unless you've asked for monthly care.
AI
AI assistants we build or use say they're AI, offer a person at any time, and treat what visitors type as information to answer — never as instructions that change what the assistant is allowed to do.
Report a problem
Found a vulnerability? Email security@datum24h.com. We reply within two business days and won't take action against good-faith research.