Security and data practices
Updated September 16, 2026
What we do to protect this site and the information you send us. Everything below is something we actually do. We hold no security certifications and claim none.
This website
- The site runs no JavaScript at all, and carries no third-party scripts, advertising trackers, or analytics cookies.
- It is served only over an encrypted connection, and browsers are instructed to refuse an unencrypted one.
- A strict content policy tells your browser to reject any script, frame, or outside resource the site does not serve itself.
- Forms post to our own domain. Nothing you type passes through a third-party form service.
Information you send us
- Inquiries and form submissions are used to answer you, and to manage a working relationship if one follows.
- Access is limited to the people who need it for the work.
- We do not sell personal information and do not use it for third-party advertising.
Please do not send confidential, classified, export-controlled, or otherwise sensitive project information through the contact forms. If an exchange needs protection, say so first and we will set up an appropriate arrangement before you send anything.
Client data and engagements
- How client data is handled, stored, retained, and deleted is set in the written agreement for that engagement, not by this page.
- Where an engagement calls for deployment inside an environment you control, that is scoped and agreed in writing.
- We do not hold a facility clearance, a government certification, or an approved cloud authorization. If a requirement depends on one, tell us early and we will say plainly whether we can meet it.
What we will not claim
No system is completely secure, and anyone who tells you otherwise is selling something. We maintain reasonable administrative, technical, and organizational safeguards suited to the work, and we will not describe them as more than that.
Reporting a problem
If you believe you have found a security issue with this site, or with anything we publish, write to security@heimdallresearch.com. Tell us what you found and how to reproduce it. We will confirm that we received it. Please give us a reasonable chance to fix it before publishing details.