Hawk Site Amp
Back to home
Trust and Compliance Center

Security and Transparency

Hawk Site Amp is committed to building a secure, trustworthy platform for our customers. This page documents our current security practices, privacy commitments, and compliance roadmap.

Compliance Status

SOC 2 Readiness

Planned

PCI-DSS Payment Handling

Stripe-Hosted / In Progress

Vendor Risk Review

In Progress

Incident Response Plan

In Progress

Privacy Program

In Progress

Important: Hawk Site Amp does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications. We are actively preparing for future third-party audits as the platform grows.

Security Overview

Hawk Site Amp is actively building a security-first compliance program and preparing for future third-party audits as the platform grows. Our infrastructure runs on hardened cloud services with encryption in transit and at rest. We enforce authentication controls, secret management, and role-based access across all admin operations. Backend functions require authenticated sessions or verified internal system secrets before executing any sensitive action.

Privacy and Data Handling

We collect only the data required to operate the platform — account information, website performance metrics, and support communications. We do not sell user data to third parties. Data is stored on secure cloud infrastructure. Users may request access to, correction of, or deletion of their data by contacting support@hawksiteamp.io. We are actively building a formal Privacy Program aligned with GDPR and CCPA principles.

Payment Security

All payment processing is handled exclusively by Stripe, a PCI-DSS Level 1 certified payment processor. Hawk Site Amp does not store, transmit, or process raw payment card data. Stripe's hosted payment pages and Stripe Elements are used to ensure cardholder data never touches our servers.

Vendor and Subprocessor Transparency

We work with a small, vetted set of third-party vendors to deliver our platform. These include Base44 (platform infrastructure), Stripe (payments), Microsoft 365 (internal communication), OpenAI (AI features), Crisp (customer support chat), and GoDaddy/WHMCS (domain and hosting services). We maintain an internal vendor risk register and conduct periodic reviews. A public subprocessor list is available on request.

Incident Response

Hawk Site Amp maintains an internal Incident Response Plan covering detection, containment, communication, and remediation. In the event of a security incident affecting user data, we commit to notifying affected users promptly and transparently. Our incident response process is reviewed periodically and is actively being formalized as part of our compliance program.

Compliance Roadmap

We are building our compliance program in stages as the platform grows. Current priorities include formalizing our Privacy Policy and Terms of Service, maintaining a vendor risk register, implementing a security controls checklist, and preparing documentation required for future third-party security audits. We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications but are actively working toward audit readiness.

Legal Policies

Security and Privacy Contact

For security disclosures, privacy questions, data requests, or compliance inquiries, please contact us at:

support@hawksiteamp.io
2026 Hawk Site Amp. All rights reserved. | Last reviewed August 2026.
base44
Edit with Base44