Security and trust
Last updated: September 26, 2026
Contents
We build software for businesses that can't afford mistakes, so we hold our own house to the same standard. This page explains, in plain words, how we protect what you share with us today.
What we keep, and for how long#
- We keep only what you send us: your name, email, company, subject and message, or the time of a call you book. We use it to reply to you.
- We never store your IP address with your message. To stop abuse we keep a one-way fingerprint of it for 7 days, then delete it.
- Messages and call requests are deleted after 24 months.
- No advertising or tracking cookies. Visits are counted in aggregate by Cloudflare, without cookies, and our own counts of button clicks carry no identifier and respect your browser's privacy signals.
Who can see your message#
- Only the ACFC Global team, through a private admin area.
- Every sign-in needs a strong password, checked against known data breaches, and a second factor.
- The server applies the same rules to every request, not just the screen, and ending a session cuts its access at once.
- Every change made in the admin area is recorded, and the record is kept for 24 months.
How this site is protected#
- Encrypted connections only (HTTPS, with browsers told to never fall back).
- The site runs only its own code and a short list of services we chose.
- Forms are protected against bots and abuse.
- The site is served by Cloudflare.
How we build#
- No change goes straight to this site: each one is proposed, checked and only then approved.
- Automated checks and tests run before every release, and a failing one stops it.
- We check the libraries we use for known vulnerabilities before releasing.
Our products#
ICM Desk has its own security design for the sensitive files immigration teams handle: each firm's data kept isolated, encryption in transit and at rest, two-factor authentication, a full audit trail, hosting on AWS and Cloudflare, and customer data that never trains AI models.
How ICM Desk protects case data
Found a security issue?#
Please write to us at [email protected] before making it public. A founder replies within 1 business day and keeps you informed until it is fixed. Please don't access other people's data or disrupt the service while testing.