Skip to content
Intake Throttle Senior-analyst hours rationed this week 7 of 12 strategy-call slots remaining · week of
DefendMyRep
    • AI Citation & Answer Defense NEW
    • Generative Engine Optimization NEW
    • Deepfake & Synthetic-Media Defense
    • Sentinel Grid Monitoring
    • Online Reputation Repair
    • Crisis PR
    • Content Removal
    • Wikipedia Management
    • Personal Brand Protection
    • Internet Privacy
    • View all services →
    • Executives & C-Suite
    • Healthcare & Medical
    • Legal & Law Firms
    • Finance & Wealth
    • Real Estate
    • View all industries →
  • About
  • Results
Take the 90-sec Audit Book Strategy Call
Services
  • AI Citation & Answer DefenseNEW
  • Generative Engine OptimizationNEW
  • Deepfake & Synthetic-Media Defense
  • Sentinel Grid Monitoring
  • Online Reputation Repair
  • Crisis PR
  • Content Removal
  • Wikipedia Management
  • Personal Brand Protection
  • Internet Privacy
  • View all services →
Industries
  • Executives & C-Suite
  • Healthcare & Medical
  • Legal & Law Firms
  • Finance & Wealth
  • Real Estate
  • View all industries →
AboutResults
Take the 90-sec Audit Book Strategy Call
Security · Updated 2026-05-24

Security at DefendMyRep

We defend reputations for executives, regulated practices, and enterprises. The security of our systems is non-negotiable because client information moves through them every day. This page documents our controls.

1. Security posture

  • Access controls — least-privilege defaults for engagement work
  • Healthcare-aware workflows — sensitive healthcare matters are scoped with confidentiality and data-minimization controls
  • Privacy requests — access, correction, and deletion requests route through the published privacy contact
  • Control mapping — internal policies are reviewed against common security and privacy frameworks as the service matures

2. Encryption

  • TLS 1.3 in transit (HSTS preload, perfect forward secrecy)
  • AES-256-GCM at rest for all engagement data
  • Encrypted backups with separate key custody

3. Authentication & access

  • Mandatory MFA (WebAuthn / TOTP) for all personnel
  • SSO (SAML 2.0 / OIDC) for client portals (enterprise tier)
  • Role-based access control with least-privilege defaults
  • Quarterly access reviews
  • Just-in-time elevation for privileged ops

4. Network & infrastructure

  • Cloudflare WAF + Bot Management at the edge
  • Strict Content-Security-Policy with `frame-ancestors 'none'`
  • Cross-Origin-Opener-Policy, Permissions-Policy hardening
  • Continuous secrets scanning across code and infrastructure
  • Centralized logging with tamper-evident retention

5. Application security

  • SAST + DAST in CI/CD
  • Dependency scanning with severity-based block gates
  • Security review before major production changes
  • Responsible disclosure program (see below)

6. People security

  • Background check before role assignment
  • Annual security awareness training
  • Phishing simulations quarterly
  • Confidentiality agreements with surviving obligations

7. Incident response

  • Documented IR plan tested twice annually
  • 60-minute internal notification window
  • Client notification within contractual SLA (typically 24 hours for confirmed material incidents)
  • Post-incident review with root-cause analysis shared in writing

8. Sub-processors

Current sub-processors with access to client data:

  • Cloudflare, Inc. — edge, hosting, WAF (US/EU)
  • Google Workspace — email, calendar (US)
  • Cal.com, Inc. — strategy-call scheduling (US/EU)
  • Resend, Inc. — transactional email (US)

Updates to this list are posted with 30 days' notice to active clients.

9. Responsible disclosure

We welcome reports from independent security researchers. Submit findings to security@defendmyrep.com with a clear PoC. We commit to:

  • Acknowledgment within 48 hours
  • Initial assessment within 5 business days
  • Remediation timeline communicated in good faith
  • No legal action against good-faith researchers operating within scope

Scope: *.defendmyrep.com and the public CF Pages deployment. Out of scope: third-party services, social-engineering attacks against personnel, denial-of-service tests.

10. Contact

Security inquiries: security@defendmyrep.com
PGP key: /.well-known/security.txt

DefendMyRep

Executive-grade reputation defense.

Ganbaru Kodo Limited
No. 5, 17/F STRAND 50
50 BONHAM STRAND, SHEUNG WAN
HONG KONG
Confidential intake Healthcare-aware workflows Crisis-response runbooks Privacy request process
Up to $20K financing

Services

  • Online Reputation Repair
  • Review Management
  • Wikipedia Management
  • Personal Brand Protection
  • Business Reputation
  • Crisis PR
  • AI Deepfake Monitoring

Industries

  • Executives & C-Suite
  • Healthcare
  • Legal
  • Finance & Wealth
  • Real Estate

Resources

  • Intel Briefings
  • 2026 Industry Ranking
  • News & Press
  • FAQ
  • Glossary
  • ORM Guide
  • PR vs ORM
  • Reputation Benefits
  • RSS Feed

Firm

  • About
  • Why DefendMyRep
  • Our Process
  • Our Team
  • Results
  • Financing
  • Contact
  • Technical Support
  • Careers
  • Affiliate Program
  • Book a Call
  • 90-sec Audit

Legal

  • Privacy
  • Terms
  • HIPAA
  • CCPA
  • Security
  • Do Not Sell
  • IP Notice
  • Refund Policy
  • Collections Policy

The First 6 Hours Decide the Next 5 Years.

One short call. Walk away with a printed defense plan.
Financing up to $20,000 available.

Book Strategy Call Take the Audit

© 2026 DefendMyRep. All rights reserved. DefendMyRep, Sentinel Protocol, Citadel Protocol, Atlas Protocol, Vault Protocol, Rapid Response Protocol, and Aperture Protocol are trademarks or service marks of DefendMyRep. DefendMyRep is a trading name of DefendMyRep.

  • Privacy
  • Terms
  • HIPAA
  • CCPA
  • Security
  • Do Not Sell
  • IP Notice
  • Collections
  • Refund
  • Sitemap