Skip to main content
Trust & transparency

Security approach

We state what is and is not in place. This page describes our current approach; it is not ISO 27001, SOC 2, government certification, or a zero-risk guarantee.

Last updated: 23 August 2026

1. Scope and honest boundaries

This page covers general security practices for 222-tech.com and client software, integration, data, and AI projects. Each project has different data, platforms, risks, and compliance needs, so actual controls are confirmed during design and in the proposal.

We do not currently claim unverified ISO 27001, SOC 2, government supplier certification, or equivalent status. If evidence, penetration testing, data location, or a specific control is mandatory, it must be scoped before work begins.

2. Website security

  • Production deployment requires end-to-end HTTPS enforcement from the edge to visitors; HTTP redirects and transport settings must be verified on every release;
  • Administration functions require authentication and are not exposed as public features;
  • The contact API validates input and limits field length and request frequency;
  • The enquiry form asks only for information needed to respond; and
  • Dependencies, configuration, and errors are reviewed and updated in proportion to risk.

No internet system can be guaranteed vulnerability-free. Improvements are prioritised according to data sensitivity, exposure, and practical risk.

3. Client project principles

  • Map the data flow first: identify what is collected, which provider receives it, who can access it, and how long it is retained;
  • Minimise data: avoid sending unnecessary information to AI services, integration platforms, or test environments;
  • Use least privilege: give accounts, API keys, and automated actions only the permissions needed;
  • Separate test and production: avoid routine testing with real sensitive data where the risk calls for separation;
  • Keep human boundaries: require approval for sensitive answers, high-impact decisions, payment, or irreversible actions where appropriate; and
  • Disclose providers: identify the AI, cloud, communications, and integration providers involved before launch.

4. Deployment, logging, and retention

Deployment location, client-controlled accounts, backups, logging, retention, deletion, administrator access, and recovery are selected for the project. General website descriptions do not mean every pilot automatically includes private cloud, on-premises deployment, a 24/7 SOC, formal disaster recovery, or forensic retention.

If you require Hong Kong-only storage, on-premises deployment, government security guidance, sector regulation, specified encryption, or audit logs, raise it during discovery. We will assess capability, cost, and feasibility before making a written commitment.

5. Security incidents

For a credible issue, we aim to determine scope, limit further impact, preserve necessary information, remediate the issue, and notify relevant clients or people as required by contract and applicable law. Response and notification timing depends on the incident and available evidence.

6. Responsible vulnerability reporting

If you believe 222-tech.com has a security vulnerability, email [email protected] with “Security report” in the subject. Include the affected URL, safe reproduction steps, observed impact, and a secure way to contact you.

Do not access, download, or alter data that is not yours; do not disrupt the service; and allow reasonable time to investigate and fix the issue before disclosure. There is no bug bounty or promise of a particular reward unless separately agreed in writing.