Skip to content
WARMACHINE33
  • Home
  • Services
  • AI Agents (soon)
  • About
  • Contact
  • Blog
  • FR
  • Diagnostic · CHF 690

Security & Responsible Disclosure

How we protect client systems, and how to report a vulnerability in good faith.

Our security posture

Security is core to what we sell. WarMachine33 (Delta-One Capital Sàrl, Geneva) designs and operates automations under Swiss data protection law (nLPD/nDSG) and GDPR. Key practices on this website:

  • HSTS (preload), strict transport security, and a Content-Security-Policy on every response.
  • X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and a restrictive Permissions-Policy.
  • Client automations run on infrastructure the client owns, your data stays under your control, not held hostage by us.
  • Payments are processed by Stripe. We never store card data.

Where your data lives

Client automations run on infrastructure the client owns — a VPS or server under your contract, hosted in Switzerland unless you decide otherwise. We host no client business data on our side. This website itself runs on Swiss infrastructure operated by Delta-One Capital Sàrl. What our website stores: contact and diagnostic requests you submit (name, email, message), payment confirmations (never card data — Stripe and CoinPayments process payments on their own systems), and standard server logs.

Who has access

  • To your systems during a build: named, least-privilege accesses that you grant and can revoke at any time — API keys scoped to the integration, mailbox delegation instead of passwords, read-only bank exports. We ask for nothing broader than the workflow needs.
  • After handover: access ends unless you keep AutoPilot maintenance, in which case it stays limited to the automations under contract and remains revocable.
  • Inside Delta-One: client access is restricted to the people working on your project.

AI models and your data

When a workflow calls an AI model, the model provider is a data processor: we set this up under your accounts and contracts, so the relationship is yours, not ours. For sensitive steps we can run open-source models on your own server so the data never leaves it. Automated decisions with significant effect always keep a human checkpoint (nLPD art. 21) — the workflow prepares, your team decides.

If something goes wrong

Incident process, in order: detect (monitoring and alerts) → contain → assess impact → notify you without undue delay with what happened, what data was involved and what we did → support your notification to the FDPIC where the nLPD requires it → written post-mortem with corrective measures. The same process applies to this website.

Reversibility and backups

Every build is handed over with documentation, credentials and code — reversibility is the default, not an option. Backups of your automations follow your infrastructure's backup policy; we help you configure one during the build if none exists. If we stop working together, your automations keep running and any competent engineer can maintain them.

Responsible disclosure policy

We welcome reports from security researchers acting in good faith. If you believe you have found a vulnerability affecting warmachine33.cloud or our services, please tell us before disclosing it publicly.

How to report: email [email protected] with a clear description, steps to reproduce, and any proof-of-concept. Encrypt sensitive details on request.

Our commitment:

  • We acknowledge reports within 72 hours.
  • We will keep you updated on remediation and credit you (if you wish) once resolved.
  • We will not pursue legal action against researchers who act in good faith, respect the scope below, and avoid privacy violations, service degradation, or data destruction.

In scope: warmachine33.cloud and its subdomains that we operate.

Out of scope / please avoid: denial-of-service, spam or social-engineering of staff or clients, physical attacks, automated scanning that degrades service, and any access to or modification of data that is not your own. Do not test third-party services (e.g. Stripe, hosting providers) — report the integration point to us instead.

Machine-readable contact details are published at /.well-known/security.txt (RFC 9116).

← Back to home

WARMACHINE33

AI automation that means business. A brand of Delta-One Capital Sàrl, Switzerland.

Solutions

  • Email Automation
  • Document Automation
  • Invoicing Automation
  • Client Onboarding
  • All 20 Solutions

Company

  • AI Agents (soon)
  • About
  • Pricing
  • Example Scenarios
  • FAQ
  • Contact
  • Blog
  • Partners

Legal

  • Impressum
  • Terms of Service
  • Privacy Policy
  • Security

© 2026 WarMachine33 — A brand of Delta-One Capital Sàrl · CHE-443.465.421. All rights reserved.

Made in Switzerland