Information Security Requirements
At AM Digital Designs, safeguarding B2B client data, proprietary software code, custom AI models, and UX participant feedback is our highest operational priority. We utilize enterprise-grade cybersecurity protocols across our Agency Services and Innovation Lab to ensure your digital assets remain strictly confidential, secure, and compliant with global data protection standards.
1. Cryptographic Standards & Data Encryption
We mandate rigorous encryption standards across our entire infrastructure to protect data from unauthorized interception or extraction:
- Data in Transit: All communications between user browsers, client portals, and our APIs are encrypted using TLS 1.3 (Transport Layer Security) with modern cipher suites.
- Data at Rest: All production databases, media storage buckets, and Innovation Lab research repositories are encrypted at rest using AES-256 (Advanced Encryption Standard).
- Credential Vaulting: AI API keys, database passwords, and third-party integration secrets are isolated in encrypted environment key vaults, never hardcoded into source code.
2. Cloud Infrastructure & Network Security
Our staging environments and managed client applications are hosted on enterprise cloud infrastructure providers that maintain strict SOC 2 Type II, ISO 27001, and HIPAA physical and network compliance standards.
- Perimeter Defense: We utilize Web Application Firewalls (WAF) and automated DDoS (Distributed Denial of Service) mitigation to block malicious traffic and brute-force attacks.
- Data Segregation: Client databases and file systems are logically segregated to prevent cross-tenant data leakage.
- Automated Backups: Mission-critical project data undergoes automated daily snapshots, stored redundantly across multiple availability zones to ensure disaster recovery (DR) capabilities.
3. Identity & Access Management (IAM)
We enforce a strict Principle of Least Privilege (PoLP) across our internal teams and engineering staff.
- Multi-Factor Authentication (MFA): MFA is strictly enforced for all administrative access to servers, code repositories (GitHub/GitLab), and Stripe billing dashboards.
- Role-Based Access Control (RBAC): Developers and researchers only have access to the specific project environments and datasets required for their active tasks.
- Access Revocation: Upon project completion or employee offboarding, all associated access credentials, SSH keys, and portal logins are immediately revoked.
4. PCI-DSS Compliance & Financial Security
AM Digital Designs does not directly process, store, or transmit full credit card numbers or bank routing data on our local servers. All payment processing, invoicing, and subscription management is securely tokenized and handled directly by Stripe, a certified PCI Service Provider Level 1 (the highest level of certification in the payments industry).
5. Innovation Lab & UX Research Data Isolation
Protecting human research participants and unreleased brand intellectual property in our Innovation Lab requires specialized research privacy controls:
- PII Anonymization: Personally Identifiable Information (PII) collected during testing is automatically decoupled from raw usability metrics and screen recordings prior to client analysis.
- Participant Non-Disclosure Agreements (NDAs): Every tester and candidate must execute a legally binding NDA before accessing unreleased client prototypes, wireframes, or spatial software.
- Storage Lifecycle: UX session recordings and prototype testing logs are archived in encrypted, access-controlled buckets and automatically purged according to project retention schedules.
6. AI Pipeline & Hardware Testbed Governance
For custom automated bots, machine learning agents, and spatial robotics prototypes:
- Zero Model Training API Endpoints: All enterprise AI connections utilize endpoints configured to strictly opt out of public model training. Client prompts and vector database queries are never ingested by third-party AI providers.
- IoT & Hardware Firmware Integrity: Microcontroller code and embedded firmware tested in our physical lab are flashed using cryptographically signed binaries to prevent malicious payload execution during spatial UI prototyping.
7. Incident Response & Breach Notification
In the unlikely event of a verified data breach compromising unencrypted personal or client data, AM Digital Designs maintains an active Incident Response Plan. We are committed to notifying affected clients within 72 hours of threat verification, in compliance with Massachusetts Data Security Regulations (201 CMR 17.00) and applicable global breach notification laws.
8. Vulnerability Management
Security is an ongoing lifecycle. We utilize automated dependency scanning (e.g., Dependabot) to identify vulnerable open-source packages in our codebases. Critical security patches for managed client care plans are applied immediately upon vendor release.
9. Reporting a Security Concern
We welcome reports from independent security researchers, clients, and research participants. If you believe you have discovered a security vulnerability on our platform or a client staging server, please report it immediately.
Contact our Security Team directly at: anam.cardenes@amdigitaldesigns.com