Scope and honest disclosures
This Trust Center covers HB Creative Inc., operating as Vantway. It describes how we run our practice, vantway.com, and the consulting engagements we deliver. It is current as of the date above and updated when a material control changes.
Some of our clients are small healthcare practices. Where an engagement requires it, we execute a Business Associate Agreement with the client, and our default posture is to keep protected health information (PHI) on client infrastructure rather than in systems we operate.
What we are not, and don't claim to be:
- We are not SOC 2 certified, ISO 27001 certified, or HIPAA-attested.
- We are not a software-as-a-service vendor running your production workloads on our infrastructure.
- We do not maintain a 24×7 on-call rotation, a security operations center, or formal published service level agreements for incident response.
What we are: a co-founder-led consultancy that takes confidentiality seriously, uses well-architected subprocessors, follows a consistent process for engagements, and writes plainly about both our strengths and our limits. If you require a formal compliance attestation, we will work with you to identify and integrate a subprocessor or partner who has it.
Information security program
Our security program is owned by the founders and applies to every team member, contractor, and engagement. The program is built around a focused set of practices that we actually follow, rather than a long policy document that nobody reads. The core controls:
- At least annually, we review subprocessors, access lists, and data inventory.
- An engagement onboarding process that covers data handling, NDA execution, and access provisioning.
- An engagement offboarding process that covers credential revocation, data return or deletion, and a post-engagement review.
- Mandatory multi-factor authentication on every internal system that supports it.
- A documented incident response approach (see section 8), reviewed at least annually.
The program is intentionally lean. Our goal is that every control on this page is one we can prove we follow if asked.
Data handling during engagements
During an engagement, we may receive business records, customer lists, financial figures, process documentation, credentials to tools we're integrating, and sample data. Our default posture:
- Collect the minimum. We ask only for what the work requires. If you can share a synthetic or redacted sample instead of a real one, please do.
- Use the client's systems when practical. When you have a secure workspace (a shared Google Drive folder, a Notion teamspace, a 1Password vault), we prefer to work inside it so the data never crosses into our environment.
- Treat credentials as restricted. API keys, service tokens, and shared passwords are stored in 1Password vaults scoped to the engagement and revoked at offboarding.
- Return or destroy on request. At engagement end, or on written request during the engagement, we delete or return client data per the SOW. Aggregated, de-identified learnings may be retained.
We do not use client data to train external AI models. See AI tools and client data.
Confidentiality and NDAs
Every engagement is covered by confidentiality obligations, either in the engagement letter itself or under a separate mutual NDA. Confidentiality survives termination for as long as the information remains confidential.
If your organization requires us to execute your standard NDA before discovery conversations, we are happy to. For most prospective clients, our standard mutual NDA is available on request.
Subprocessors
These are the third parties that may process client information in the course of running our practice. We evaluate each on security posture, data residency, and contractual commitments before adoption. We update this list when it changes.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | vantway.com hosting and analytics | USA |
| Stripe | Invoicing and payment processing | USA |
| Resend | Transactional email delivery for contact form submissions | USA |
| Google Workspace | Email, documents, calendar, internal storage | USA |
Engagement-specific tools (such as an AI platform we connect into your stack) are scoped per SOW and are not listed here unless they process data on our behalf.
Encryption standards
In transit. All traffic to vantway.com is served over HTTPS with TLS 1.2 or higher. We enforce HSTS so browsers refuse to downgrade. Public APIs we operate require TLS.
At rest. Data stored in our subprocessors' systems is encrypted using AES-256 (or stronger as the provider supports). Examples:
| Where | How |
|---|---|
| Google Workspace files and email | AES-256 at rest, TLS in transit |
| 1Password vaults | End-to-end encrypted with a per-account secret key |
| Stripe payment data | PCI-DSS compliant, encrypted by the provider |
Local workstations used by team members have full-disk encryption enabled (FileVault).
Access control
- Every team member uses a unique account on every system. No shared logins.
- Multi-factor authentication is enabled on every system that supports it, using a hardware key or an authenticator app rather than SMS.
- Access to client engagement materials is granted on a need-to-know basis and removed at offboarding or role change.
- Production access (where applicable to a client engagement) follows the principle of least privilege and is logged by the underlying platform.
- Shared client credentials, when needed, live only in 1Password vaults scoped to the engagement, and are rotated when the engagement ends.
Incident response
An incident is any event that compromises (or is reasonably likely to have compromised) the confidentiality, integrity, or availability of client data or our systems. Our response plan:
| Severity | Definition | Initial response target |
|---|---|---|
| Critical | Confirmed compromise of client data, credentials, or systems we are responsible for. | Within 24 hours of confirmation |
| High | Strong indicators of compromise; loss of access to a critical engagement system. | Within 2 business days |
| Medium | Vulnerability or process gap that could lead to compromise if unaddressed. | Within 1 week |
| Low | Informational findings, minor misconfigurations, or single-user issues. | Within 2 weeks |
Our process: contain the issue, investigate what happened and what was affected, notify affected clients in plain language, remediate the underlying cause, and document what changed so we don't repeat the mistake. We aim to give affected clients an initial notice within the response targets above and a written post-incident summary within ten business days of containment, including timeline, root cause, scope, and remediation.
We do not have a 24×7 on-call rotation. If you believe you are observing an active incident, email hello@vantway.com with "[INCIDENT]" in the subject line.
Vulnerability management
- Operating systems and browsers on team devices are kept on the current major release with automatic security updates enabled.
- Dependencies in projects we maintain are reviewed at least quarterly, and on advisory notifications, using GitHub's Dependabot and npm audit. Critical advisories are patched within 14 days; high advisories within 30 days.
- Our subprocessors handle infrastructure-level patching for the systems they operate.
- Findings reported through responsible disclosure (section 13) are triaged within 5 business days.
Business continuity
Our continuity strategy is built around managed services rather than self-hosted infrastructure. The most consequential dependencies for our practice are Google Workspace, Vercel, Supabase, and Stripe, all of which provide their own redundancy and recovery commitments.
- Client engagement materials live in Google Drive, which provides built-in version history and recovery.
- Production source code is hosted in GitHub, which provides redundancy at the platform level.
- Engagement-critical credentials live in 1Password, accessible to designated team members.
AI tools and client data
Vantway builds AI workflows, which means we use AI models, including frontier large language models, in our own work. Our handling rules for client data and AI:
- When working with client data, we use AI tools configured so that prompts and outputs are not used to train the provider's models.
- We do not paste regulated, sensitive, or identifying client data into consumer chat tools that train on conversations.
- When an engagement requires a strict data residency or no-third-party-AI constraint, we work within those constraints rather than around them.
- For deliverables that include AI-generated content, we disclose it and review before delivery.
Acceptable use
By using vantway.com or our services, you agree not to use them to:
- Violate applicable law or any third party's rights.
- Send unsolicited bulk communications, malware, or fraudulent content.
- Probe, scan, or test the security of our systems without prior written permission (see Responsible disclosure).
- Reverse engineer or attempt to extract proprietary methodologies or content.
- Discriminate against any person or group, or generate content that promotes violence or exploitation.
We reserve the right to terminate access for material violations.
Responsible disclosure
If you've found a security issue with vantway.com or with software we maintain, we'd genuinely like to hear about it. Email hello@vantway.com with "[SECURITY]" in the subject line and include enough detail for us to reproduce the issue. We don't currently run a paid bug bounty, but we will:
- Acknowledge your report within 5 business days.
- Investigate and keep you updated on progress.
- Credit you publicly (with your permission) once the issue is resolved.
- Not pursue legal action against good-faith research that respects user privacy, avoids destructive testing, and gives us reasonable time to fix before public disclosure.
Contact
Security questions, vendor risk reviews, or a request for our standard NDA all go to the same place.
Talk to the team
For active incident reports, prefix the subject line with [INCIDENT]. For vulnerability reports, prefix with [SECURITY]. For everything else, just say hi.