How we protect client systems, and how to report a vulnerability in good faith.
Security is core to what we sell. WarMachine33 (Delta-One Capital Sàrl, Geneva) designs and operates automations under Swiss data protection law (nLPD/nDSG) and GDPR. Key practices on this website:
X-Frame-Options: DENY, X-Content-Type-Options: nosniff, and a restrictive Permissions-Policy.Client automations run on infrastructure the client owns — a VPS or server under your contract, hosted in Switzerland unless you decide otherwise. We host no client business data on our side. This website itself runs on Swiss infrastructure operated by Delta-One Capital Sàrl. What our website stores: contact and diagnostic requests you submit (name, email, message), payment confirmations (never card data — Stripe and CoinPayments process payments on their own systems), and standard server logs.
When a workflow calls an AI model, the model provider is a data processor: we set this up under your accounts and contracts, so the relationship is yours, not ours. For sensitive steps we can run open-source models on your own server so the data never leaves it. Automated decisions with significant effect always keep a human checkpoint (nLPD art. 21) — the workflow prepares, your team decides.
Incident process, in order: detect (monitoring and alerts) → contain → assess impact → notify you without undue delay with what happened, what data was involved and what we did → support your notification to the FDPIC where the nLPD requires it → written post-mortem with corrective measures. The same process applies to this website.
Every build is handed over with documentation, credentials and code — reversibility is the default, not an option. Backups of your automations follow your infrastructure's backup policy; we help you configure one during the build if none exists. If we stop working together, your automations keep running and any competent engineer can maintain them.
We welcome reports from security researchers acting in good faith. If you believe you have found a vulnerability affecting warmachine33.cloud or our services, please tell us before disclosing it publicly.
How to report: email [email protected] with a clear description, steps to reproduce, and any proof-of-concept. Encrypt sensitive details on request.
Our commitment:
In scope: warmachine33.cloud and its subdomains that we operate.
Out of scope / please avoid: denial-of-service, spam or social-engineering of staff or clients, physical attacks, automated scanning that degrades service, and any access to or modification of data that is not your own. Do not test third-party services (e.g. Stripe, hosting providers) — report the integration point to us instead.
Machine-readable contact details are published at /.well-known/security.txt (RFC 9116).