Legal Documentation
Security Statement
Security responsibilities, service-dependent safeguards and how to report a concern.
This Security Statement describes the security approach for Good Ground Serves LLC’s SiteHeros services. The scope of a particular service and its configured controls is defined by the applicable Agreement and service schedule.
This is a high-level description, not an audit report, certification, warranty, service-level agreement, promise of perfect security or representation that every described control is implemented identically in every system.
1. Governance
Our security approach is designed around ownership, data and system inventories, risk assessment, approved access, vendor review, change control, incident response, backup and recovery, and documented verification.
2. Access and identity
Controls are designed to include:
- individual accounts and least privilege;
- owner approval for privileged, production, destructive, payment, legal, customer-data, or access-changing actions;
- multifactor authentication where supported and appropriate;
- restricted credential storage and secure transfer;
- periodic review of users, devices, sessions, applications, OAuth scopes, service identities and external sharing;
- prompt revocation or change when access is no longer required; and
- separation of recommendations, approvals, implementation, and verification for material changes.
3. Data protection
Our intended controls include data minimization, purpose limitation, role-based access, provider encryption in transit and at rest where available, secure transmission methods, retention schedules, defensible deletion, logging, backups, and legal holds.
Customers must not send credentials, full payment-card data, protected health information, government identifiers, children’s information, or other regulated/sensitive data through ordinary email, forms, tickets, or AI tools unless SiteHeros expressly approves a secure method and service scope.
4. Application and infrastructure security
Depending on the Service, SiteHeros and its providers may use:
- managed hosting, patching and supported software;
- firewalls, content delivery networks, TLS/SSL, malware and abuse controls;
- backups and restoration procedures;
- uptime, integrity or security monitoring;
- code/configuration review, test and rollback planning; and
- vulnerability identification and remediation.
Exact coverage, frequency, retention, ownership, service targets, and exclusions are defined by the applicable agreement or service schedule. A security feature available from a provider is not evidence that it is enabled for a customer.
5. Vendors and subprocessors
Our vendor-review approach considers the service, data, access, contract, security documentation, processing chain, transfers, retention, incident terms and exit plan. The scope and available assurance depend on the particular provider and service.
We may rely on third-party infrastructure and security certifications within their stated scope. Their certifications do not certify SiteHeros, and their service commitments are not SiteHeros commitments unless expressly incorporated.
6. Secure development and changes
Material changes should be bounded, reviewed, tested, backed up where appropriate, approved, documented, and verified. Production changes must have a defined target, authorized implementer, rollback approach, evidence, and stop conditions.
Generated or third-party code must be reviewed for function, security, licensing, secrets, dependencies, and accessibility before production use.
7. Backups and recovery
Backup and recovery depend on the selected Service, platform and configuration. Backups are intended to support operational recovery; they are not permanent archives or legal holds. No backup is guaranteed to contain every change or restore successfully.
Customers remain responsible for any independent backups, exports, records, or business-continuity measures assigned to them in the Agreement.
8. Incident response
Our incident-response approach is designed to:
- receive and triage reports;
- preserve relevant evidence and a factual timeline;
- contain harm under authorized procedures;
- assess affected systems, information, customers, vendors and legal/contract clocks;
- coordinate recovery and communication;
- make notification decisions under applicable law and contract; and
- document corrective action and closure.
Report security events promptly to legal@siteheros.com. Do not send exploit details or sensitive data through an unapproved channel; ask for a secure method. Nothing here prohibits lawful good-faith reporting or communication with authorities.
9. Vulnerability reports
Report a suspected vulnerability to legal@siteheros.com with the affected URL or asset and a minimal description. Ask for written scope before testing. Do not access another person’s data, disrupt service, degrade availability, use social engineering, target third parties or violate law or provider terms. No testing authorization or bug bounty is created by this Statement.
10. Customer responsibilities
Customers must:
- secure their users, endpoints, networks, accounts, credentials and recovery methods;
- maintain accurate authorized contacts;
- use supported software and follow required updates;
- avoid installing unapproved or unlicensed components;
- notify SiteHeros of suspected compromise or material changes;
- maintain lawful content and configurations;
- review security recommendations and act on assigned risks; and
- maintain business continuity, legal, insurance and incident obligations outside SiteHeros’ scope.
11. Compliance and attestations
SiteHeros does not claim PCI DSS, HIPAA, SOC, ISO, FedRAMP, CMMC, GDPR, or other certification merely because a provider has one or because SiteHeros follows a framework.
Security reports or questionnaires may be provided under confidentiality and only after validation. No customer may represent that SiteHeros holds a certification without written authorization.
12. Contact
Security reports: legal@siteheros.com.
Legal notices: legal@siteheros.com.
Emergency support availability exists only if stated in an executed Service schedule.