Security & Data Practices
How we protect the data entrusted to us.
Last updated July 23, 2026. This statement describes the current practices of Dawncrest Consulting LLC ("Dawncrest," "we," "us"). It is provided for transparency and vendor-diligence purposes and does not create contractual obligations except where incorporated into a signed agreement.
1. Scope
This statement covers the systems we operate: this website, the tools published from our lab (including the AI Exposure Calculator, Form D Explorer, and Data Barnacle), and client engagements where we build and operate software. Where a client engagement is governed by a signed agreement, that agreement controls.
2. Encryption
All traffic between your browser and our systems is encrypted in transit using TLS. Data at rest is stored on managed cloud infrastructure that provides disk-level encryption. We do not transmit or accept sensitive information over unencrypted channels.
3. Hosting and infrastructure
Our production systems are hosted on Railway, a managed cloud platform running on infrastructure located in the United States. We do not operate physical servers. Platform-level physical security, network isolation, and hardware maintenance are managed by our hosting provider.
4. Subprocessors
We use a small number of established service providers to operate our systems. Each processes only the data necessary for its function:
- Railway — application hosting and databases.
- Stripe — payment processing. Card numbers are entered directly with Stripe, a PCI-DSS Level 1 certified provider; we never receive, store, or transmit full card numbers.
- Anthropic — AI processing for AI-powered features.
- Google — site analytics and advertising measurement, as described in our Privacy Policy.
5. Access control
Access to production systems and data is restricted to personnel who require it, protected by strong authentication, and limited to the minimum necessary. Administrative interfaces are not exposed to public search engines and are access-controlled.
6. Data handling and retention
We collect only what a given feature needs to function: assessment responses you submit, an email address if you choose to provide one, and the contents of inquiries you send us. We do not sell personal information, and we do not share it with third parties except the subprocessors listed above. You may request deletion of your data at any time by writing to luke@dawncrestconsulting.com, and we will honor verified requests without undue delay.
7. Secure development
Software is developed in-house. Changes are version-controlled, dependencies are pinned and reviewed, user input is validated server-side, and standard protections against common web vulnerabilities (including CSRF, injection, and abuse rate-limiting) are enabled at the framework level.
8. Incident response
If we determine that a security incident has affected personal information, we will notify affected individuals and, where applicable, affected client firms without undue delay, consistent with applicable law. Suspected vulnerabilities may be reported to luke@dawncrestconsulting.com; good-faith reports are welcomed.
9. Certifications and diligence
Dawncrest does not currently hold SOC 2 or ISO 27001 certification, and we will not represent otherwise. We are glad to complete vendor due-diligence and security questionnaires for prospective client firms, and to discuss engagement-specific requirements — including data residency, compliance review, and audit support — before work begins.
10. Contact
Questions about this statement or our practices: luke@dawncrestconsulting.com
Dawncrest Consulting LLC, 27929 Ridgebluff Ct, Rancho Palos Verdes, CA