Scroll to top
Trust Center

How we handle and protect your information

We hold ourselves to the standards we deliver.

Last updated: June 2026

Our commitment

We advise clients on security for a living, so we hold our own operations to the same standards we recommend, scaled appropriately to a boutique, remote-first firm. This page describes, honestly, how we work with your information. We don't overstate our infrastructure, and we're glad to walk through any of this in detail.

How we handle client data

Engagements vary. Advisory work may involve little or no access to your systems. Hands-on implementation work often requires access to client environments, configurations, and, in some cases, data, including sensitive data, in order to build and verify controls. We're direct about this rather than claiming we never touch your data.

When we do have access, we apply these principles:

  • Least privilege. We request only the access an engagement actually requires, and for only as long as it's needed.
  • Defined scope. Access, purpose, and handling are agreed in writing before work begins, and documented in the engagement contract.
  • Return or removal. At the end of an engagement, client data and credentials we hold are returned or securely removed on request.
  • Confidentiality. Client information is covered by mutual NDA and contractual confidentiality terms.

Our security posture

The practices we maintain across our own operations include:

  • Multi-factor authentication on business-critical accounts and all administrative access
  • Encryption in transit (TLS) and full-disk encryption on company devices
  • Reputable cloud and SaaS providers that maintain their own recognized attestations (for example SOC 2 or ISO 27001) for the infrastructure underneath our tools
  • Endpoint protection and timely patching on company devices
  • Least-privilege access and periodic access review
  • A documented approach to incident handling and client notification

We describe what we actually do. Where a capability is provided by a third party, we attribute it to that provider rather than presenting it as our own infrastructure.

Subprocessors and vendors

We rely on established third-party providers for email, storage, productivity, and security tooling. We choose vendors that maintain recognized security practices, and we can share our current list of subprocessors with clients on request under NDA.

Responsible disclosure

If you believe you've found a security vulnerability in our website or systems, we want to hear about it. Email contact@launchsecureconsulting.com with the details. We'll acknowledge your report within two business days and work with you in good faith to confirm and address the issue. We appreciate responsible disclosure and won't pursue researchers who act in good faith and avoid privacy violations or service disruption.

Frameworks we deliver

Across client engagements we build toward and support:

SOC 2 ISO 27001 HIPAA PCI-DSS NIST CSF FedRAMP GovRAMP

Questions or documentation requests

For security questions, due-diligence requests, or to discuss what we can share under NDA:

LaunchSecure Consulting
Email: contact@launchsecureconsulting.com
Phone: +1 (313) 401-4946

Doing diligence on us?

We're happy to complete security questionnaires and share our subprocessor list and practices under NDA. Reach out and we'll turn it around quickly.

Talk to Us
Report a vulnerability

contact@launchsecureconsulting.com
Acknowledged within two business days.