Security & SLA
Last updated: August 9, 2026
1. Overview
This page describes the security practices Pennom Agency LLC ("Pennom," "we," "us") applies to our own systems and to client work, and the service-level commitments we make to clients regarding response times, support, and warranty coverage.
Formal, contractual Service Level Agreements — including uptime percentages, service credits, and compliance frameworks such as SOC 2 — are defined in a signed Enterprise Service Agreement for clients who require them, as referenced on our Pricing page. The commitments below describe our standard practice for all engagements.
2. Data Security Practices
We apply the following baseline security practices across our own systems:
- All traffic to our Site and admin systems is encrypted in transit via SSL/TLS.
- Administrator passwords are never stored in plain text — they are salted and hashed with bcrypt before being saved, and password fields are stripped from API responses before they leave the server.
- Access to our admin portal (used to manage blog content, inquiries, and administrator accounts) requires authentication via signed, time-limited JSON Web Tokens (JWTs) and is restricted to authorized Pennom staff.
- Our admin portal and internal API routes are excluded from search engine indexing via our robots.txt configuration.
- Client inquiry data is stored in a managed MongoDB Atlas database; associated media files are stored via Cloudflare's object storage network.
3. Security Practices We Build Into Client Projects
Where applicable to the scope of your project, our development engagements can include security-conscious defaults such as rate-limited and JWT-authenticated API routes, edge middleware security controls, and zero-trust auth token management for sensitive applications (for example, our Full Next.js Web App and Enterprise engagement tiers).
The exact security controls implemented for your project depend on its scope and are documented in your Service Agreement.
4. Response Time Commitments
We aim to meet the following response times for active clients and prospects:
- New project inquiries submitted through our contact form: response within 4 business hours.
- Dedicated Engineering Team retainer clients: average 48-hour turnaround on queued feature/task requests, plus a weekly strategy and architecture sync call.
- Production issues reported by active retainer clients are prioritized ahead of new feature work.
5. Post-Launch Warranty Coverage
Completed development engagements include a post-launch warranty period during which we fix bugs in the work we delivered at no additional charge — 30 days for landing page engagements and 60 days for full web application engagements, as outlined on our Pricing page. Warranty coverage does not extend to new feature requests or issues introduced by changes made outside of Pennom after launch.
6. Uptime & Enterprise SLAs
We do not publish a single blanket uptime guarantee on this page, because actual uptime depends on the hosting environment chosen for your specific project (Cloud Hosting or Shared Hosting) and the infrastructure provider behind it.
Clients with formal uptime, compliance (including SOC 2), or dedicated-team SLA requirements can request a Custom Enterprise Scope, where these terms — including any service credits — are defined explicitly in a signed agreement.
7. Incident Response
If we become aware of a security incident that has compromised client data we hold, we will investigate promptly and notify affected clients without undue delay, along with the steps we are taking to address it, consistent with applicable law.
8. Your Responsibilities
- Use strong, unique credentials for any admin dashboards, hosting accounts, or third-party tools we set up on your behalf.
- Promptly revoke access for former employees or contractors on accounts you control.
- Notify us promptly if you suspect unauthorized access to systems we manage or maintain for you.
9. Reporting a Security Issue
If you believe you have discovered a security vulnerability affecting pennom.com or our systems, please report it to us responsibly by emailing hello@pennom.com or calling +1 (215) 444-3535 rather than disclosing it publicly. We will acknowledge good-faith reports and work to address confirmed issues promptly.
10. Changes to This Page
We may update this page as our security practices and service commitments evolve. The "Last updated" date above reflects the most recent revision.
11. Contact Us
Questions about our security practices or service-level commitments can be sent through our contact form, by phone at +1 (215) 444-3535, or by email at hello@pennom.com.
