DOC NO. LG-06 / LEGAL
Security Policy
This page describes the security practices we actually apply, and how to report a vulnerability to us. It is a statement of practice, not a certification claim.
- Effective
- January 1, 2026
- Issued by
- The Factory Deals LLC
- Governing law
- State of Delaware, USA
Scope and honesty about certification
We hold no security certifications and we do not claim any. What follows is a description of the controls we operate. If your procurement process requires a specific certification, tell us during the brief so you are not surprised later.
Access control
- Least-privilege access to client systems: we request only the roles the work requires.
- Multi-factor authentication on accounts that support it, including cloud consoles, repositories and ad platforms.
- Credentials held in a password manager, never in repositories, tickets or chat messages.
- Access reviewed when project staffing changes and removed at the end of an engagement.
Application security practices
- Input validation on both client and server for anything that reaches a database.
- Parameterised queries and row-level security policies rather than trusting application-side checks alone.
- Secrets kept in the platform's secret store and read only in server-side code.
- Dependency updates applied on a regular cadence, with advisories reviewed before release.
- Separate staging and production environments with isolated credentials and data.
Data handling
Data in transit is protected with TLS. Data at rest is stored in managed services with encryption enabled by the provider. We avoid copying production data into development environments; where test data is needed, it is generated or anonymised.
Backups and recovery
Client databases we operate are configured with automated backups and a documented restore procedure. A backup that has never been restored is not a backup, so we test restoration as part of project QA.
Incident response
If we become aware of a security incident affecting a client system we operate, we notify the client's named contact promptly, contain the issue, preserve logs, and provide a written summary of what happened, what was affected and what changed as a result. Where a notification obligation applies under law, we support the client in meeting it.
Reporting a vulnerability
Email admin@thefactorydeals.com with the subject line "Security". Please include the affected URL or system, the steps to reproduce, and what you observed. We acknowledge reports within three business days.
Please do not access, modify or delete data belonging to others, do not run denial-of-service or automated scanning against our systems, and give us a reasonable period to remediate before disclosing publicly. We will not pursue legal action against researchers who follow these guidelines in good faith. We do not currently operate a paid bug bounty.
Questions about this document
Write to The Factory Deals LLC at admin@thefactorydeals.com or 175 SW 7th Street STE 1517-1263, Miami, FL 33130, United States.
SEC-07 / CONTACT
Tell us what you need built.
Send the brief, the deadline, and the budget range. We reply to all enquiries within one business day during our published hours.
Start a project- Legal name
- The Factory Deals LLC
- Entity
- Limited Liability Company, State of Delaware, United States
- Address
- 175 SW 7th Street STE 1517-1263, Miami, FL 33130, United States
- Phone
- +1 (307) 289-2860
- Hours
- Monday–Friday, 09:00–14:00 EST