Every line here is a factual claim we have to be able to prove today. Anything we cannot prove is not on the page. This page describes controls, not outcomes, and it does not modify the warranty disclaimer in section 24 of the Terms of Service.
1What Buzzmax runs today
Being straight about the size of the attack surface is more useful than a page of controls for systems we do not operate. As of the date at the top of this page:
- buzzmax.ai is a static website. It has no login, no database and no server-side application. It stores nothing about you.
- There is no client dashboard yet. Client work is delivered directly and reported by email.
- The personal information we hold is held inside the third-party services listed in section 5, not on infrastructure we built.
When a dashboard exists, this page changes before it launches, not after.
2Encryption in transit
buzzmax.ai is served over HTTPS only, and every service we use for email, messaging and payments is reached over TLS. We do not send personal information over an unencrypted connection.
3Encryption at rest
Data at rest sits inside the services in section 5 and is encrypted by those providers under their own published practices. We do not operate our own database, so we make no separate claim about our own storage. We will not describe anything here as "bank-level" or "military-grade", because neither phrase means anything.
4Who can get at data
Production access is limited to one person, the founder. No contractor, agency or third party has standing access to client or end-customer data. Every vendor account in section 5 is protected by multi-factor authentication.
As the team grows, access will be granted by role on a least-privilege basis and this section will say so and name the roles.
5Subprocessors
These are the third parties that process data on our behalf. We keep this list current and give clients notice before adding one. All are based in the United States.
| Subprocessor | What it does | Data it touches | Location |
|---|---|---|---|
| Twilio | Delivers review request text messages | Mobile number, message body | United States |
| Resend | Sends transactional and outbound email | Email address, message body | United States |
| Google Workspace | Our own email and documents | Anything sent to us by email | United States |
| Stripe | Takes payment | Client billing details and card data, which go to Stripe directly | United States |
| Cerebras | Drafts review replies for a client to approve | Review text | United States |
| OpenRouter | Fallback for reply drafting when Cerebras is unavailable | Review text | United States |
| Spaceship | Domain registrar for buzzmax.ai | None | United States |
| Vercel | Hosts and serves buzzmax.ai | Visitor IP address and request logs | United States |
6How long we keep data
The retention periods are set out by category in section 4 of the Privacy Policy, so there is one table to keep current rather than two.
7If something goes wrong
If we confirm a security incident affecting a client's data, we notify that client without undue delay and in no event later than 72 hours after confirmation, with what we know, what we are doing about it, and what they need to do. The same 72 hour commitment appears in the Terms of Service and the Privacy Policy.
We maintain a written incident response plan and review it annually. It covers what counts as an incident, how we contain it, how we assess what was affected, who we notify and when, and how we close it out.
8Logging
The vendors in section 5 keep their own access and delivery logs under their own retention policies. Buzzmax does not operate an application of its own, so there is no separate administrative audit log to describe. When there is one, this section will say what it records and for how long.
9Payment data
Buzzmax does not store cardholder data. Payments are processed by Stripe, and card details go to Stripe directly without passing through anything we run.
10Independent audit status
Buzzmax has not completed a SOC 2 examination and is not SOC 2 certified. We are a small company and we have not been audited. We would rather tell you that than imply otherwise.
We do not display any certification mark, trust seal or auditor logo that we have not earned.
11Reporting a vulnerability
Email team@buzzmax.ai. We will acknowledge within five business days. We will not pursue you for good-faith research that respects user privacy and does not degrade the service.
12What this page does not say
We describe controls, not results. No provider can promise that data is safe, and we do not. Security is a set of measures against a moving threat, and this page is a statement of what those measures are today.