A little clarity goes a long way
Security begins with care.
Clear access, considered changes, and a practical conversation about protecting your environment.
Effective September 15, 2026
A focused website
This is an informational website. It has no customer sign-in, payment collection, or database for contact submissions. The contact form prepares a draft in your email application; you decide whether to send it.
Hosting and email still involve processing information. Our privacy policy explains those practices. This website is not a channel for exchanging credentials or sensitive project data.
Security starts with the scope
Cloud administration requires clear authorization and a shared understanding of responsibility. Before an engagement, we discuss the controls appropriate to the environment and document the agreed scope. Topics include:
- Access: named accounts, multi-factor authentication, and permissions limited to the work.
- Changes: approval for production changes, testing, and a rollback plan where appropriate.
- Data: what information is involved, where it belongs, and how it may be accessed or transferred.
- Recovery: who owns backups, recovery testing, and service continuity.
- Handover: documentation, ownership, and removal of access when work ends.
Specific controls and support commitments depend on the signed agreement and the capabilities of the selected platforms. This page is not a security certification, audit report, or guarantee that any system is free of risk.
Share sensitive information carefully
Keep your initial inquiry to a description of the project. Do not email passwords, MFA codes, recovery codes, private keys, production exports, or regulated personal data.
When access or sensitive material is required for agreed work, arrange the access method and transfer channel first. You should retain ownership and administrative control of your business accounts.
Report a security concern
If you believe you have found a security issue affecting this website, email carlos@pathy.cc with the subject “Security report.” Include the affected page, a description, approximate discovery time, and minimal steps to reproduce it.
Remove personal information and secrets from screenshots or examples. If sensitive evidence is necessary, describe what you have and ask for an appropriate way to share it.
Please avoid accessing other people’s data, changing or deleting information, disrupting service, or testing third-party infrastructure. Stop if you encounter private information. Publishing this contact does not authorize intrusive testing or create a bug bounty program.
Incidents & support
The public contact email is not an emergency or continuously monitored incident response channel. Existing clients should follow the support and incident procedures in their agreement. For urgent issues with a cloud provider account, use that provider’s available support and account recovery channels.
Questions about security expectations for a potential project are welcome at carlos@pathy.cc.