Legal

Security

Last updated August 2026

What we actually do to protect data, in enough detail to be checkable, and nothing we cannot prove.

Ground rules for this page

Every line here is a factual claim we have to be able to prove today. Anything we cannot prove is not on the page. This page describes controls, not outcomes, and it does not modify the warranty disclaimer in section 24 of the Terms of Service.

1What Buzzmax runs today

Being straight about the size of the attack surface is more useful than a page of controls for systems we do not operate. As of the date at the top of this page:

When a dashboard exists, this page changes before it launches, not after.

2Encryption in transit

buzzmax.ai is served over HTTPS only, and every service we use for email, messaging and payments is reached over TLS. We do not send personal information over an unencrypted connection.

3Encryption at rest

Data at rest sits inside the services in section 5 and is encrypted by those providers under their own published practices. We do not operate our own database, so we make no separate claim about our own storage. We will not describe anything here as "bank-level" or "military-grade", because neither phrase means anything.

4Who can get at data

Production access is limited to one person, the founder. No contractor, agency or third party has standing access to client or end-customer data. Every vendor account in section 5 is protected by multi-factor authentication.

As the team grows, access will be granted by role on a least-privilege basis and this section will say so and name the roles.

5Subprocessors

These are the third parties that process data on our behalf. We keep this list current and give clients notice before adding one. All are based in the United States.

SubprocessorWhat it doesData it touchesLocation
TwilioDelivers review request text messagesMobile number, message bodyUnited States
ResendSends transactional and outbound emailEmail address, message bodyUnited States
Google WorkspaceOur own email and documentsAnything sent to us by emailUnited States
StripeTakes paymentClient billing details and card data, which go to Stripe directlyUnited States
CerebrasDrafts review replies for a client to approveReview textUnited States
OpenRouterFallback for reply drafting when Cerebras is unavailableReview textUnited States
SpaceshipDomain registrar for buzzmax.aiNoneUnited States
VercelHosts and serves buzzmax.aiVisitor IP address and request logsUnited States

6How long we keep data

The retention periods are set out by category in section 4 of the Privacy Policy, so there is one table to keep current rather than two.

7If something goes wrong

If we confirm a security incident affecting a client's data, we notify that client without undue delay and in no event later than 72 hours after confirmation, with what we know, what we are doing about it, and what they need to do. The same 72 hour commitment appears in the Terms of Service and the Privacy Policy.

We maintain a written incident response plan and review it annually. It covers what counts as an incident, how we contain it, how we assess what was affected, who we notify and when, and how we close it out.

8Logging

The vendors in section 5 keep their own access and delivery logs under their own retention policies. Buzzmax does not operate an application of its own, so there is no separate administrative audit log to describe. When there is one, this section will say what it records and for how long.

9Payment data

Buzzmax does not store cardholder data. Payments are processed by Stripe, and card details go to Stripe directly without passing through anything we run.

10Independent audit status

Buzzmax has not completed a SOC 2 examination and is not SOC 2 certified. We are a small company and we have not been audited. We would rather tell you that than imply otherwise.

We do not display any certification mark, trust seal or auditor logo that we have not earned.

11Reporting a vulnerability

Email team@buzzmax.ai. We will acknowledge within five business days. We will not pursue you for good-faith research that respects user privacy and does not degrade the service.

12What this page does not say

We describe controls, not results. No provider can promise that data is safe, and we do not. Security is a set of measures against a moving threat, and this page is a statement of what those measures are today.