Scope of this page
This Trust & Security page describes the public security posture for Rusty Harbor's website and typical client work. A signed scope sheet, DPA, NDA, or security addendum may add project-specific controls.
We use static-first architecture, HTTPS, least-privilege access, careful credential handling, and clear incident response practices.
We are candid about limits: this is not a SOC 2 or regulated-hosting trust center unless a client project separately scopes that work.
This Trust & Security page describes the public security posture for Rusty Harbor's website and typical client work. A signed scope sheet, DPA, NDA, or security addendum may add project-specific controls.
Client projects may use hosting, DNS, analytics, form, booking, CMS, email, payment, repository, and monitoring vendors chosen for the project. We disclose material vendors in the scope, handoff notes, or on request. We prefer vendors that support HTTPS, access controls, exportability, and reasonable data processing terms.
If we discover a security incident affecting Rusty Harbor systems or client work under our active care, we investigate, contain the issue, preserve useful evidence, notify affected clients when appropriate, and support legally required breach notifications.
Please report suspected vulnerabilities to security@rustyharborseo.com. Include the affected URL, steps to reproduce, impact, and your contact information. Do not access, alter, delete, exfiltrate, or publicly disclose data that is not yours.
Rusty Harbor is a small web development and SEO studio. We do not currently claim SOC 2, ISO 27001, PCI-DSS, HIPAA, or FedRAMP certification for our own business. If a client project requires a regulated environment, that requirement must be raised before signature and scoped with qualified counsel or auditors.