HOW THINGS ACTUALLY WORK HERE

Trust & Security

This page describes exactly what this website does with your data and payments — no invented certifications, no vague marketing language. If something changes about how we handle data, this page gets updated first.

Contact form

When you submit the contact form, it is sent by email directly to AC IA SUPPORT through Resend and is not saved in any database on our side. The connection is encrypted (HTTPS) end to end.

  • Every submission is validated on the server (not just in the browser) before anything is sent.
  • A hidden honeypot field and an origin check silently filter out automated bot/spam submissions.
  • Your message content is sanitized before being placed in the notification email, to prevent injection tricks.

Payments

Card payments on /pay are processed entirely by Stripe, a PCI-DSS Level 1 certified payment processor. Your card number, expiration date and CVC are typed directly into Stripe's own secure checkout — AC IA SUPPORT's servers never see or store raw card data.

  • The amount you're charged is calculated and verified on our server for every transaction — never trusted from the browser.
  • Payment confirmations arrive through a webhook whose signature is cryptographically verified, so a forged or replayed request is rejected.
  • We keep transaction records that Stripe provides (amount, status, receipt) — not the underlying card details, which Stripe never shares with us in the first place.

Site-wide protections

This site ships with the following browser-enforced security headers on every page (you can verify these yourself with any HTTP header inspector):

  • Strict-Transport-Security — forces every visit over HTTPS, never plain HTTP.
  • Content-Security-Policy — restricts which scripts/styles/domains are allowed to run on this site at all, reducing the impact of any injected code.
  • X-Frame-Options: DENY — this site can never be embedded in someone else's page to trick a visitor (clickjacking).
  • X-Content-Type-Options: nosniff — stops the browser from misinterpreting file types in a way attackers can exploit.
  • Referrer-Policy and Permissions-Policy — limit what's shared with other sites and which device features (camera, mic, location) a page can even ask for.

What we don't do

  • We don't run any third-party analytics or ad-tracking scripts (no Google Analytics, no Meta Pixel, no session recorders) on this site today.
  • We don't sell, rent or share your contact information with anyone.
  • We don't claim certifications we don't hold — if a badge or compliance claim isn't listed on this page, we haven't earned it yet.

Questions about any of this? Ask directly — we'll give you a straight answer.

Contact Us