Security & Trust
Your data, handled deliberately
We are a small Utah IT partner, so we cannot hide behind a badge. What we can do is describe exactly how we protect your information — and only claim what we can demonstrate.
What we do today
Each of these is a control we test, not an aspiration.
Access is authenticated and least-privilege
Every internal API route requires a signed-in user with a specific permission, and role permissions are minimal. Passwords are stored only as bcrypt hashes, and two-factor authentication (an authenticator app) can be required for any account — it is enforced at sign-in once enabled.
Encrypted in transit
Everything between your browser and us travels over TLS 1.2 or higher (currently TLS 1.3), with HSTS enabled so an unencrypted first request cannot be downgraded. Certificates renew automatically and their expiry is checked every five minutes.
Encrypted at rest, and encrypted backups
Database storage sits on encrypted block storage, the database is never exposed to the internet, and a backup is encrypted before it leaves the server. A backup only counts once it has been read back and proven, and the restore path is rehearsed rather than assumed.
A human approves anything that leaves the building
Nothing is emailed to a prospect or client and no price is finalised without an explicit approval by a person. Opt-out requests are honoured when a draft is created and checked again at send time, and the record of an opt-out is never deleted.
We keep the minimum, and we can delete
Website analytics, chat transcripts and AI records have defined expiry dates; enquiries are kept as a business record. Ask us to delete your data and we remove your contact details, redact the words you typed, and keep only the note that you asked us not to be contacted again.
Everything important is logged
Sign-ins, approvals, outbound sends, data purges and deletion requests are written to an audit trail, so any question about what happened to a record has an answer.
Checked every five minutes, and monitored around the clock
The website, the API, TLS certificate expiry, container health, disk headroom, database liveness and backup freshness are checked every five minutes against the live system, and a failure emails a person with the details. Twenty checks run today, and the alert path has been proven with a real delivered message.
Backups are proven, not assumed
An encrypted database backup is taken every night and one is restored into a throwaway database every month, with the row counts compared to production — the encrypted copy is read back and compared before the unencrypted one is deleted, so a backup that cannot be restored is never reported as a success.
We have been scanned from the outside
An OWASP ZAP baseline scan has been run against the live website and API. It reports no failures, and every warning is either fixed in code or waived in writing with a reason. The scan is re-run as we ship changes.
What we do not claim
Trust is easier to check when the limits are stated up front.
- We are not SOC 2 or ISO 27001 certified, and we do not claim to be. We can describe the specific controls above and demonstrate them working.
- We do not encrypt individual fields inside the database beyond what the storage layer provides — protection at rest is disk-level encryption plus encrypted backups.
- Our client application is not yet multi-tenant. It runs one Commteck instance for our own operations and is deliberately not reachable from the internet while that work is completed.
- We are not a system of record for patient information. For dental and medical clients, IT support that touches patient data happens inside your own systems under a signed business associate agreement — patient data is not put into this platform.
Being switched on now
Built, tested and in rollout — each item moves up to the list above as it goes live, and this page carries a review date so you can see it is maintained.
- Offsite copies of those backups: the nightly encrypted backup and the monthly restore drill already run on our production host — replicating the encrypted copies to separate storage is the next step.
- An independent dead-man's switch, plus host-level CPU, memory and disk alerts, so a machine that is entirely offline — or quietly unhealthy — is noticed too. Today's five-minute checks run on the host they watch.
- An active (non-passive) vulnerability scan against a staging copy of the stack, and a public summary of what was found and fixed.
- DMARC and CAA records that lock down our email and certificate issuance.
Report a security issue
Found something that looks wrong? Tell us and we will confirm receipt, investigate, and tell you what we found. Email helpdesk@commteck.net, or see our disclosure details at /.well-known/security.txt. Please do not test against our live services in a way that affects other people.
Last reviewed: 5 October 2026. Questions about how we handle your data are welcome before you become a client — ask, and we will answer in writing.
Ask us a security question