Encrypted connections, always
All web properties operated by Anchored Logic use HTTPS with current TLS certificates. HTTP connections redirect to HTTPS at the server level. Client communication over email uses standard transport-layer encryption provided by our mail provider.
We do not transmit sensitive business information over unencrypted channels. If a secure file-sharing method is required for your engagement, we will establish one before transfer begins.
Access to your systems
When an engagement requires access to your platforms — website hosting, CRM, automation tools, analytics — we follow a minimum-necessary access policy:
- We request only the permission level required to complete the specific work
- Credentials are never stored in code, documentation, or shared repositories
- All API keys and tokens are stored in the credential managers provided by the platforms themselves
- We do not hold access after project delivery — all credentials are revoked or transferred to you at handover
- We recommend you use multi-factor authentication on every account before granting us access
What we collect and why
We collect only what is necessary to respond to inquiries and deliver services. This means:
- Name and contact information provided through booking or contact forms
- Business context shared during discovery and project work
- Analytics data collected through Google Analytics 4 (aggregated, not personally identified)
We do not sell personal information. We do not share it with third parties except as required to deliver services (for example, Calendly for scheduling). We do not use client business information for any purpose other than delivering the engagement it was shared for.
Platforms we use in engagements
When we build automation or AI systems for clients, those systems may involve third-party platforms. Before integrating any service that will touch client or customer data, we evaluate:
- Where the data goes and in which country it is stored
- Whether the service has a published security and compliance posture
- What the service's breach notification policy is
- Whether a data processing agreement is required
We document these decisions and include them in every engagement's handover package so you know exactly what is connected to what — and can make informed decisions about what stays connected after we hand over.
If something goes wrong
In the event of a security incident affecting any work we have delivered or are actively managing, we will:
- Contain the issue immediately and revoke any compromised credentials
- Notify you directly and in writing as soon as the scope is understood
- Provide a factual account of what happened, what was affected, and what was done
- Remediate and document the vulnerability to prevent recurrence
We do not speculate about cause before an assessment is complete. We do not obscure or delay disclosure.
To report a security concern:
Email emily@anchoredlogic.com with the subject line "Security." We respond within one business day.
Document currency
This page was last reviewed in July 2026. If you have questions about any security practice not addressed here, contact us directly — we would rather answer a specific question than have you guess.