Legal
Security
How this site is built, and how to tell us about a problem in it or in something we built for you.
This website
This site is a set of static pages. It has no database, no login, no user accounts and no forms, so there is nothing on it to breach and no credentials of yours for it to hold.
It is served over HTTPS. The only third-party code on it is the Cal.com booking embed on the contact page.
Reporting something
If you have found a security problem in this site, or in software SpazorLabs built for you, email info@spazorlabs.com with enough detail for us to reproduce it. Both founders see that inbox.
We will confirm we have it, tell you what we find, and tell you when it is fixed. We will not threaten you for reporting it in good faith.
If it is urgent, the founders' direct numbers are on the contact page. Use them.
How we work on client systems
Client work runs in infrastructure the client owns, under accounts the client controls and can revoke. We do not keep copies of client production data, and access is arranged for the engagement rather than held afterwards.
Specific obligations, including anything a regulated client needs, are set in the agreement for that engagement rather than described here.
Certifications
SpazorLabs holds ISO/IEC 27001 for information security, ISO 9001 for quality management, ISO/IEC 20000-1 for IT service management, ISO 22301 for business continuity, ISO/IEC 27701 for privacy, and ISO/IEC 42001 for AI management.
This page describes how the site is built and how to report a problem. It is not the certificate. If a procurement process needs the certificate itself, ask and we will send it.