Security Policy
Effective Date: 20-May-2025
Last Updated: 22-April-2025
SVTech Consulting, LLC (“SVTech,” “we,” “our,” or “us”) is a single-member limited-liability company committed to protecting client information—including payment data processed through Stripe. This Security Policy outlines the practical, proportionate safeguards we maintain as both service provider and security officer.
1 Governance and Responsibility
-
As the sole member–manager, we design, implement, and review all security controls at least once per year—or sooner if laws, Stripe requirements, or the threat landscape change.
-
Any independent contractor we engage must sign a confidentiality and data-protection agreement before receiving client information.
2 Payment-Card Data Protection
-
We never store raw cardholder data. All payments flow directly through Stripe’s PCI DSS Level 1 infrastructure.
-
Our website and payment links use HTTPS with TLS 1.2+.
-
Stripe Radar, 3-D Secure, and address verification are enabled to mitigate fraud.
3 Encryption of Data in Transit and at Rest
-
All client files travel over encrypted channels (HTTPS, S/MIME, or secure file-share links).
-
Deliverables, recordings, and project notes reside on encrypted disk volumes (AES-256) within a zero-trust cloud account. Our local workstation is full-disk-encrypted.
4 Access Control and Authentication
-
We work from a single, dedicated workstation protected by strong OS-level credentials and a hardware security key (FIDO2) for MFA.
-
Every cloud dashboard or repo uses MFA and, where supported, IP-restricted logins.
-
Access logs are retained and reviewed monthly for anomalies.
5 Endpoint and Network Security
-
The workstation runs auto-updating EDR/antivirus and a reputable firewall.
-
System and application patches install within 72 hours of release (24 hours for critical CVEs).
-
Guest Wi-Fi is segmented from the work network when clients visit onsite.
6 Backup, Continuity, and Incident Response
-
Project data is backed up nightly to encrypted, geographically separate storage; backups are retained 30 days.
-
If an incident occurs, we will (i) contain it within four hours of discovery, (ii) complete root-cause analysis within 48 hours, and (iii) notify affected clients and, where applicable, Stripe without undue delay, consistent with GDPR/CCPA breach-notification rules.
7 Third-Party Service Providers
-
Besides Stripe, any third-party tool that handles client files (e.g., transcription or cloud storage) must publish SOC 2 or ISO 27001 attestations (or equivalent).
-
We review each provider’s security posture annually.
8 Data Retention and Destruction
-
Client deliverables are retained for 12 months unless a longer period is legally required or mutually agreed.
-
At the end of the retention period—or upon verified client request—we securely erase files using NIST SP 800-88 compliant methods.
9 Client Responsibilities
-
Use strong, unique passwords for any shared portals and enable MFA where possible.
-
Never email raw payment details; always use the secure Stripe link we provide.
-
Report any suspected security issue immediately to security@svtechconsultingservices.com.
10 Policy Updates
Material changes take effect 14 days after posting. Continued use of our services after that date signifies acceptance.
11 Contact
Security questions or concerns?
Email: mike@svtechconsultingservices.com
Phone: +1 (301) 244-9221
Mailing Address:
SVTech Consulting, LLC
30N Gould St Ste R
Sheridan Wy 82801
USA
By engaging SVTech Consulting, LLC, you confirm that you have read, understood, and agree to this Security Policy.
Contact Us
Phone: +1 (301) 244-9221
mike@svtechonsultingservices.com
Newsletter
Return Policy – Link
As we provide virtual services, returns are not applicable – Click here for the Full Return Policy. However, if you are not satisfied with our services, please contact us at mike@svtechconsultingservices.com within 30 days of the service date to discuss a potential refund or resolution.
Refund Policy – Link
Refunds for virtual services are processed within 7 business days after the resolution of the issue – Click here for the Full Refund Policy. If you have any concerns or disputes, please contact us at mike@svtechconsultingservices.com. We will work with you to resolve any issues.
Cancellation Policy
To cancel a scheduled service, please contact us at mike@svtechconsultingservices.com at least 24 hours before the appointment time. Cancellations made less than 24 hours in advance may not be eligible for a refund. Click here for the full Cancellation Policy.
Legal Restrictions
Our virtual services comply with all applicable laws and regulations. Customers are responsible for ensuring that their use of our services complies with local laws. Click here for the Full Legal Restriction Policy.
Transaction Currency
All transactions are processed in USD (United States Dollars).
Security Policy
We use industry-standard encryption to protect your payment card details during transmission. All transactions are secured using SSL (Secure Socket Layer) technology to ensure your information is safe. Click here for the Full Security Policy.
Privacy Policy
Your privacy is important to us. We collect and use your personal information only as necessary to provide our services. We do not share your data with third parties without your consent. For more details, please read our full Privacy Policy
