LEGAL

Compliance, Security & Disclosure

EFFECTIVE JULY 2026 · REDTORCH, INC.

Licensing & conduct

Investigative work is performed under applicable state licensing and in accordance with the laws of the jurisdictions where we operate. We decline engagements that would require otherwise — a policy that has cost us revenue and never once been regretted.

Regulatory posture

Our platform enforces provenance, sanitization lineage, and regulatory mapping by construction — the GRC module operates at the same level as investigative doctrine. Frameworks we actively map against include GDPR, CCPA, the EU AI Act, DORA, CIRCIA, CMMC 2.0, and MTSA. Details of how this works are on theTechnology page.

Website security

This website is deliberately boring: static pages, no client-side data storage beyond a theme preference, no dynamic backend to attack. Forms route to a hardened third-party endpoint. We consider a small attack surface a feature, and we recommend the same to our clients.

Responsible disclosure

Found something? Report it to info@redtorch.com with the subject "Security disclosure." We acknowledge within two business days, we do not pursue good-faith researchers, and we credit findings where the reporter wishes.

Accessibility

We aim for WCAG 2.1 AA across this site — semantic structure, keyboard navigability, and contrast-checked palettes in both themes. If something is hard to use, tell us atinfo@redtorch.com and we will fix it.