SECURITY  /  VECTOR PACIFICO

Security
practices.

LAST UPDATED10 October 2026
CERTIFICATIONNone
REPORT A VULNERABILITYconsult@vectorpacifico.com

This page describes how Vector Pacifico protects its website, its systems, and the information entrusted to it. Our practices are modeled on the ISO/IEC 27001 information security framework.

We are not certified to ISO/IEC 27001 or to any other standard. Nothing on this site is a certification, an attestation, or a guarantee that no security incident will occur.

The public website is served over HTTPS, with HTTP Strict Transport Security enabled.

The public website has no user accounts and no payment forms. Contact is by email only.

Analytics on the website is provided by a third party. See the privacy policy for what is collected.

The following controls are planned and are not yet verified as in place. We will update this page when each one is done.

Security headers: content security policy, frame protection, referrer policy, and permissions policy.

Multi-factor authentication on every administrative, hosting, domain registrar, and cloud account.

Dependency scanning and updates for website code.

Backups with recorded restore tests.

A written incident response procedure, a vulnerability log, and a quarterly access review.

Personal data is handled as described in the privacy policy. We do not sell personal data or client information to anyone.

Information we hold is limited to what is needed for the purpose it was collected for.

If you believe you have found a security problem in a Vector Pacifico system, email consult@vectorpacifico.com with a description of the issue and the steps needed to reproduce it. Please do not test against systems you do not own or have permission to test, and do not access data that is not yours.

We read every report and will tell you what we are doing about it.

When a security incident affects personal data, we investigate it, act to contain it, and notify affected people and authorities where the law requires.

We update this page when our practices change, and we change the date at the top when we do.