Legal
Security Overview
Our public security posture for website inquiries, project materials and AI-Agent workflows.
Updated: 2026-05-27
Principles
Collect and process only what is necessary.
Limit access to people who need it.
Keep important workflow changes traceable.
Define data boundaries before connecting tools or AI systems.
Website security
Forms use captcha and server-side validation to reduce spam and abuse.
Admin functions are not exposed as public operations.
Sensitive configuration should stay in environment variables, not frontend code.
Project materials
Use anonymized samples and summaries whenever possible.
Sensitive employee, candidate, patient-path, financial, customer or contract data should be governed by written project terms.
Project folders, permissions and archival rules should be agreed during kickoff.
Incident response
If unauthorized access or a high-risk mistake is suspected, we first contain, assess and document impact.
Client-data incidents should be handled according to contract and applicable law.
To exercise data rights, request a DPA, report a security issue or discuss high-risk service boundaries, contactceo@analyzefocus.com.