security + data protection.
we run growth systems that touch our clients' stores, ad accounts, and customer data. that's a trust we take literally. this page is our published information security and data protection program: what we protect, how, and who answers when something needs attention.
who we are
forward deployed labs llc (d/b/a convey growth) is a US limited liability company (wyoming). two principals own and operate every system named below. security questions, reports, or data requests: hello@conveygrowth.com.
the program
our security and compliance work is governed by a documented internal standard we call the ship gate: twenty-two controls across disclosure and policy, data handling, application security, reliability, and AI-specific duties. every site, app, and integration we ship is audited against it before deploy, and the standard is versioned as it evolves. this page is the public statement of that program.
infrastructure + network
- production workloads run on managed cloud platforms (serverless hosting and managed postgres) with provider-enforced isolation between services.
- self-managed servers are single-purpose, one service per host, with inbound access restricted to required ports only.
- all traffic to and between our services runs over TLS. no plaintext transport, anywhere.
- automated monitors watch production endpoints and self-heal or alert on failure.
endpoints
- company endpoints are macOS machines with built-in anti-malware (XProtect) and Gatekeeper enabled, receiving OS security updates automatically.
- screens lock when idle. devices are operated only by the two principals.
operational baseline
- multi-factor authentication on every critical business account: email, hosting, code, ad platforms, and partner portals.
- strong, unique passwords per service. no shared passwords, no password reuse.
- work happens on named accounts, never anonymous or shared logins.
access control
- least privilege, always. API tokens are scoped to the minimum needed, read-only wherever the job allows.
- client credentials are isolated per client. one client's keys never touch another client's systems.
- secrets live in environment vaults, never in code, never in repositories, never in documents.
- client systems are accessed through named collaborator or partner accounts that the client grants and can revoke at any time. we never ask for passwords.
- anyone working with us signs an NDA and IP agreement before receiving access to any system.
data classification + encryption
- we classify what we handle in three tiers: public (published work), business (client operational data), and sensitive (personal data and credentials). handling rules tighten by tier.
- data in transit is TLS-encrypted. data at rest sits on managed platforms with provider-managed AES-256 encryption.
- personal data stays inside the client-authorized platforms it came from (the client's store, email platform, or ad accounts). we do not copy customer lists onto local machines.
incident response
- the two principals own detection, containment, remediation, and notification. no incident waits on a committee.
- monitored alert channels and automated watchdogs surface failures and anomalies as they happen.
- if an incident touches a client's data or a partner platform, that client or partner is notified without undue delay through their designated contact, with what happened, what was affected, and what we did about it.
- every incident gets a root-cause fix, not a patch-and-forget.
vulnerability management
- automated scanning runs across our repositories: static analysis (semgrep), secrets detection (gitleaks), and dependency vulnerability checks (osv-scanner).
- findings are triaged, fixed at the root, and re-scanned to verify the fix landed. the tooling is built to find and fix, not just report.
- dependencies are kept current; known-vulnerable versions are upgraded or removed.
personal data handling
- our full privacy practice is published at conveygrowth.com/privacy.
- we assist any client or platform partner in honoring user requests to access, correct, delete, or export personal data.
- at the end of a contractual relationship, we delete collected customer data in our possession and revoke our own access.
- data we process is stored and processed in the united states.
breach notification
suspected or identified breaches are escalated to both principals immediately. affected clients and platform partners are notified without undue delay via their designated contacts, and regulators are notified where the law requires it. in the past three years we have had no breach requiring notification and no complaint from any data protection authority or customer regarding our processing of personal data.
certifications
we hold no third-party certifications (ISO 27001, SOC 2) at our current size, and we won't pretend otherwise. the controls above are real, in force, and verifiable in conversation with either principal.
changes
material changes to this program get reflected on this page. the version line below tells you when we last touched it.
last updated · 2026-08-31
← back to convey