Hawk Site Amp is committed to building a secure, trustworthy platform for our customers. This page documents our current security practices, privacy commitments, and compliance roadmap.
SOC 2 Readiness
Planned
PCI-DSS Payment Handling
Stripe-Hosted / In Progress
Vendor Risk Review
In Progress
Incident Response Plan
In Progress
Privacy Program
In Progress
Important: Hawk Site Amp does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications. We are actively preparing for future third-party audits as the platform grows.
Hawk Site Amp is actively building a security-first compliance program and preparing for future third-party audits as the platform grows. Our infrastructure runs on hardened cloud services with encryption in transit and at rest. We enforce authentication controls, secret management, and role-based access across all admin operations. Backend functions require authenticated sessions or verified internal system secrets before executing any sensitive action.
We collect only the data required to operate the platform — account information, website performance metrics, and support communications. We do not sell user data to third parties. Data is stored on secure cloud infrastructure. Users may request access to, correction of, or deletion of their data by contacting support@hawksiteamp.io. We are actively building a formal Privacy Program aligned with GDPR and CCPA principles.
All payment processing is handled exclusively by Stripe, a PCI-DSS Level 1 certified payment processor. Hawk Site Amp does not store, transmit, or process raw payment card data. Stripe's hosted payment pages and Stripe Elements are used to ensure cardholder data never touches our servers.
We work with a small, vetted set of third-party vendors to deliver our platform. These include Base44 (platform infrastructure), Stripe (payments), Microsoft 365 (internal communication), OpenAI (AI features), Crisp (customer support chat), and GoDaddy/WHMCS (domain and hosting services). We maintain an internal vendor risk register and conduct periodic reviews. A public subprocessor list is available on request.
Hawk Site Amp maintains an internal Incident Response Plan covering detection, containment, communication, and remediation. In the event of a security incident affecting user data, we commit to notifying affected users promptly and transparently. Our incident response process is reviewed periodically and is actively being formalized as part of our compliance program.
We are building our compliance program in stages as the platform grows. Current priorities include formalizing our Privacy Policy and Terms of Service, maintaining a vendor risk register, implementing a security controls checklist, and preparing documentation required for future third-party security audits. We do not currently hold SOC 2, ISO 27001, HIPAA, or PCI certifications but are actively working toward audit readiness.
For security disclosures, privacy questions, data requests, or compliance inquiries, please contact us at:
support@hawksiteamp.io