Security at Tech Sirocco

Trust begins with deliberate foundations.

We approach security as an ongoing engineering responsibility. Our practices will continue to mature with our products and their risk profiles.

Our approach

Practical security principles.

These statements describe our current approach; they are not claims of external certification.

Secure development

Security considerations are included in product design, code review, testing, and release practices.

Cloud foundations

We design cloud environments with managed services, clear operational controls, and appropriate isolation.

Least privilege

Identities and systems should receive only the access needed for their defined purpose.

Encryption in transit

Our public website enforces HTTPS to protect information while it travels between visitors and the service.

Dependency management

We monitor software dependencies, assess reported vulnerabilities, and plan remediation according to risk.

Responsible disclosure

We welcome clear, good-faith reports that help us investigate potential security issues.

Responsible disclosure

Report a security concern.

If you believe you have found a vulnerability affecting Tech Sirocco’s website or a product, please provide a clear description, affected location, reproduction steps, and potential impact. Do not access data that is not your own or disrupt services.

Email security@techsirocco.com