HOW THINGS ACTUALLY WORK HERE
Trust & Security
This page describes exactly what this website does with your data and payments — no invented certifications, no vague marketing language. If something changes about how we handle data, this page gets updated first.
Contact form
When you submit the contact form, it is sent by email directly to AC IA SUPPORT through Resend and is not saved in any database on our side. The connection is encrypted (HTTPS) end to end.
- Every submission is validated on the server (not just in the browser) before anything is sent.
- A hidden honeypot field and an origin check silently filter out automated bot/spam submissions.
- Your message content is sanitized before being placed in the notification email, to prevent injection tricks.
Payments
Card payments on /pay are processed entirely by Stripe, a PCI-DSS Level 1 certified payment processor. Your card number, expiration date and CVC are typed directly into Stripe's own secure checkout — AC IA SUPPORT's servers never see or store raw card data.
- The amount you're charged is calculated and verified on our server for every transaction — never trusted from the browser.
- Payment confirmations arrive through a webhook whose signature is cryptographically verified, so a forged or replayed request is rejected.
- We keep transaction records that Stripe provides (amount, status, receipt) — not the underlying card details, which Stripe never shares with us in the first place.
AI & automation safeguards
When we build a custom AI agent or automation workflow for a client (using platforms like OpenAI, Make.com, Zapier, n8n and Python), your business data stays scoped to that project.
- Your data is never used to train public AI models — it stays inside the systems built for you.
- Access to it is limited to what each specific integration actually needs to function (least-privilege, not blanket access).
- We take reasonable, standard precautions against common AI-specific risks, like input designed to try to manipulate an agent's instructions — no AI system's safeguards are absolute, which is also addressed in our Terms of Service.
Engineering & site-wide protections
Every system we build starts from a security-conscious engineering mindset: inputs are validated on the server (never trusted just because they came from a browser), credentials and API keys are scoped to the minimum access each integration needs, and this site itself ships with the following browser-enforced security headers on every page (verify them yourself with any HTTP header inspector):
This site ships with the following browser-enforced security headers on every page (you can verify these yourself with any HTTP header inspector):
- Strict-Transport-Security — forces every visit over HTTPS, never plain HTTP.
- Content-Security-Policy — restricts which scripts/styles/domains are allowed to run on this site at all, reducing the impact of any injected code.
- X-Frame-Options: DENY — this site can never be embedded in someone else's page to trick a visitor (clickjacking).
- X-Content-Type-Options: nosniff — stops the browser from misinterpreting file types in a way attackers can exploit.
- Referrer-Policy and Permissions-Policy — limit what's shared with other sites and which device features (camera, mic, location) a page can even ask for.
Florida law compliance
AC IA SUPPORT operates from the State of Florida and takes its obligations under the Florida Information Protection Act (FIPA) seriously with respect to any protected personal or business information we handle. We use commercially reasonable security measures — encryption in transit, scoped access, and deliberate data lifecycle management (see "Engineering & site-wide protections" above).
In the unlikely event of a security incident affecting protected information, Florida law requires notification generally within 30 days of determining a breach occurred — we're committed to meeting that timeline. Separately, the Florida Digital Bill of Rights (FDBR) mainly applies to much larger technology companies by revenue, but we voluntarily align with its core principles of transparency, data minimization and user control anyway.
OSINT operating integrity
Our OSINT research service is conducted with the same discipline as everything else on this page: we operate strictly within the bounds of public-data access law — never unauthorized surveillance, never breaching protected databases or accounts, never violating an individual's privacy rights. Every due-diligence, verification or brand-protection engagement is collected transparently and requires a clear, lawful purpose from the client, so the intelligence we deliver is legally sound and ethically sourced.
What we don't do
- We don't run any third-party analytics or ad-tracking scripts (no Google Analytics, no Meta Pixel, no session recorders) on this site today.
- We don't sell, rent or share your contact information with anyone.
- We don't claim certifications, frameworks or compliance programs we don't actually hold — if a badge or specific claim isn't listed on this page, we haven't earned it yet.
Questions about any of this? Ask directly — we'll give you a straight answer.
See also our Privacy Policy and Terms of Service.
Contact Us