Security

Last updated: September 13, 2026

AlphaOriginal LLC is a small, independent software company. This page says plainly how we protect the information our products and this website handle, and how to reach us if you find a problem. Everything here is true today, not a goal.

How we run security

This website

alphaoriginal.co is a static site with no JavaScript, no analytics, and no cookies. It is served over HTTPS with HTTP Strict Transport Security and a strict Content Security Policy. The only personal information it collects is what you type into the contact form, which is handled by our host, Netlify, and deleted within twelve months. Details are in our privacy policy.

Our products

Reporting a vulnerability

If you believe you have found a security issue in this site or any of our products, email security@alphaoriginal.co. Tell us what you found, where, and how to reproduce it. We will acknowledge your report within five business days, keep you informed while we fix it, and credit you if you would like. We do not run a bounty program.

We welcome good-faith research. If you make a genuine effort to avoid privacy violations, data destruction, and service disruption, and you give us reasonable time to fix an issue before disclosing it, we will not pursue legal action against you for that research. Our machine-readable contact details are at /.well-known/security.txt.

Questions

Business partners who need our full policy documentation for a security review can request it through the contact form; we share it under a non-disclosure agreement.