Trust
Trust and security
Armage builds systems that carry a company's reputation, so the way we build and run them is part of the product. This page states what we actually do — on this website, with the information you send us, and in the systems we deliver.
Third-party code
None on this site
Backups
Nightly, encrypted, restore-tested
Access
Least privilege, separated by environment
Disclosure
90-day coordinated target
01
How this website is built
- Nothing loads from other companies. No third-party scripts, fonts, embeds, advertising or analytics. Everything the page needs is served from arm-age.com.
- A strict content policy. The browser is told to block everything by default; each script the site needs is allowed by its exact file name, and inline scripts are rejected at build time.
- Encrypted in transit. HTTPS everywhere, with strict certificate validation, signed DNS and an enforced email authentication policy for mail sent as Armage.
- Forms are protected without tracking you. Rate limiting and simple server-side checks replace tracking-based bot detection; the forms work without JavaScript.
- Accessibility is part of security of access. See our accessibility statement.
02
What we collect, and for how long
- Only what you send. The enquiry and application forms collect the details in those forms. The site sets no analytics or advertising cookies.
- Kept for a limited time. Enquiries up to 24 months after our last contact; applications up to 12 months after a decision, unless a contract or the law requires longer.
- Never health information. The forms ask you not to send patient or medical details, and Armage does not build this site to receive them.
- Your rights. How to ask for a copy, correction or deletion is in the privacy statement, along with our response times.
03
How we protect the systems we build
- Least privilege by default. Each part of a system gets its own credential with the narrowest rights that work: the public website can only read published content, and approval of official statements requires a separate credential that automated systems never hold.
- Separation of environments. Test environments use synthetic data and cannot reach production credentials. Builds refuse to ship if sample content is present.
- A tamper-evident record. Content and media changes are recorded by the database itself in a linked chain that cannot be edited or deleted by the applications.
- Backups that are proven, not assumed. Nightly encrypted backups are restored into a clean database and checked automatically before they are stored; they are kept off the main provider and expire on a schedule.
- Media is reviewed before it is public. Every image or video is checked, recorded with its source and rights, and stays private until a person clears it.
04
Reliability and what happens in an outage
- Watched from outside. Automated checks run every fifteen minutes from outside our hosting, so an outage cannot hide itself. Sustained failures raise an alert.
- Degrades honestly. If the content database is unavailable, pages that were already published keep serving from cache, and anything that cannot be served says so instead of showing something misleading.
- Reversible releases. Every change ships through automated checks and can be rolled back to the previous released version.
05
Reporting a vulnerability
If you believe you have found a security problem, email security@arm-age.com. Please give us enough detail to reproduce it, and time to fix it before publishing.
Our vulnerability disclosure policy sets out what is in scope, the safe harbour for good-faith research and our 90-day coordinated disclosure target. Machine-readable contact details are published at /.well-known/security.txt.
06
What we do not claim
- Armage holds no security certification today, and does not describe itself as compliant with any standard. When an independent audit exists, it will be stated here with its date and scope.
- We do not name clients or publish their work without their written approval, so you will not find logos here that we were not given permission to show.
- We do not publish performance or uptime figures we cannot evidence from our own monitoring.
Questions
- Does arm-age.com track visitors?
- No. The site loads no third-party scripts, fonts, embeds or advertising, and sets no analytics or advertising cookies.
- Where does information from the forms go?
- Enquiries and applications are sent to Armage by email and kept for a limited time: enquiries up to 24 months after our last contact, applications up to 12 months after a decision.
- Is Armage certified against a security standard?
- No. Armage holds no security certification today and does not claim one. This page describes the controls that are actually in place.
- How do I report a security problem?
- Email security@arm-age.com. Our vulnerability disclosure policy explains scope, safe harbour and our 90-day coordinated disclosure target.
Questions about how we work?
Security questions before a project, or a due-diligence questionnaire: write to hello@arm-age.com or start a project.