Security & Data Practices
A plain-language overview of the safeguards built into this public website and the controls that should precede any exchange of client data.
Last updated: August 25, 2026
This website is intentionally data-minimized. It provides public information and an outbound WhatsApp link; it does not include a HERO-operated web form, user account, file upload, advertising pixel, or analytics tool.
1. Public website safeguards
- HTTPS is used for encrypted transport to the hosted site.
- Browser security headers restrict framing, content types, referrer information, device permissions, and unapproved content sources.
- The site does not accept passwords, payments, files, or financial records.
- Outbound links open separately and use protections that prevent the new page from controlling the original page.
2. What not to send through WhatsApp
Do not send account or routing numbers, Social Security numbers, passwords, private keys, system credentials, security findings, regulated customer information, health data, privileged material, or confidential company records through an initial WhatsApp inquiry. Provide only enough high-level context to schedule a conversation.
3. Before client data is accessed
A prospective engagement involving nonpublic or regulated information should not begin until the parties document the service scope, permitted data, roles, access method, confidentiality obligations, retention, deletion, incident notification, sub-processors, and any legally required data-processing or service-provider terms.
4. Financial-sector data
If work may involve customer information from a financial institution, the parties should evaluate the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, regulator-specific requirements, and contractual service-provider controls before HERO receives access. The applicable requirements depend on the parties, information, services, and regulators involved.
5. Practical engagement controls
Depending on risk and scope, appropriate controls may include least-privilege access, multi-factor authentication, approved secure transfer channels, access logging, encryption, separate workspaces, data minimization, defined retention, secure deletion, personnel confidentiality, incident procedures, and periodic control review. Specific controls must be confirmed in the engagement documents.
6. No certification claim
This page describes current website features and a risk-based approach for future engagements. It does not state or imply that HERO is certified under SOC 2, ISO 27001, PCI DSS, FedRAMP, or another framework unless HERO separately provides current written evidence.
7. Security questions or reports
To report a suspected website security issue, contact HERO through WhatsApp at +1 (870) 666-0440. Share only a high-level description at first. Do not include exploit code, credentials, personal data, or confidential evidence until an appropriate secure channel is agreed.
Security is a shared and ongoing responsibility. No website, communication channel, or control can eliminate every risk.