Security at iAmaran
Last Updated: August 18, 2026
At iAmaran Technologies LLC, we recognize that security is an important part of delivering dependable technology and consulting services. We take a risk-based approach designed to protect our website, business systems, customer communications, and information entrusted to us. Specific controls may vary depending on the services provided, customer requirements, contractual commitments, and the systems involved.
Our Security Approach
Our security practices are guided by the following principles:
- Collect and retain only information reasonably needed for legitimate business purposes
- Limit access to information based on business need
- Use reputable infrastructure and technology providers
- Protect information during transmission where supported
- Keep systems, software, and dependencies reasonably current
- Evaluate security considerations during solution design and delivery
- Respond to suspected security incidents in a timely and responsible manner
- Review and improve practices as our services and risk environment evolve
Website and Infrastructure Security
Our public website uses HTTPS to encrypt supported communications between a visitor’s browser and the website.
We use professional hosting and infrastructure providers that maintain their own physical, network, and platform security measures. We also seek to apply appropriate website, deployment, domain, and access controls based on the nature of the environment.
No internet-connected system is completely secure. HTTPS and other safeguards reduce risk but cannot guarantee that unauthorized access, interception, or disruption will never occur.
Access Control
Where appropriate for the relevant systems and services, we seek to use measures such as:
- Individual user accounts
- Role-based or need-based access
- Strong authentication
- Multifactor authentication where available and appropriate
- Restricted administrative privileges
- Periodic removal or adjustment of unnecessary access
- Separation of development, testing, and production access when required
The exact controls used for a customer project will depend on the applicable agreement, technical environment, and customer requirements.
Secure Development and Change Management
For software and integration work, security considerations may include:
- Reviewing requirements and data flows
- Limiting exposure of credentials and sensitive information
- Using supported libraries and dependencies
- Performing code reviews and testing appropriate to the project
- Separating configuration from source code
- Protecting production credentials
- Controlling deployments and production changes
- Logging relevant errors and system events
- Addressing identified vulnerabilities based on risk and priority
Any project-specific security testing, penetration testing, regulatory validation, or compliance certification must be expressly included in the applicable statement of work or agreement.
Data Protection
We seek to protect business and customer information using safeguards appropriate to the sensitivity of the information and the relevant environment.
These safeguards may include:
- Encryption in transit
- Access restrictions
- Secure cloud or hosting services
- Controlled file and credential sharing
- Backup and recovery measures
- Data minimization
- Retention and disposal practices
- Contractual requirements for service providers
Customers and website visitors should not send passwords, private keys, financial account details, Social Security numbers, health information, immigration documents, or other highly sensitive information through ordinary email or public website forms.
If sensitive information must be exchanged for an authorized project, the parties should agree on an appropriate secure method.
Third-Party Providers
We may rely on third-party providers for services such as website hosting, cloud infrastructure, email, analytics, communications, source-code management, and business operations.
We consider the nature of the service and information involved when selecting and using providers. However, each provider operates its own systems and is responsible for its respective security practices.
Customer Environments
When iAmaran performs work within a customer-controlled environment, security responsibilities may be shared among iAmaran, the customer, and relevant technology providers.
Customers remain responsible for matters under their control, including:
- Authorizing users and access
- Maintaining their infrastructure and endpoint security
- Providing accurate security and compliance requirements
- Reviewing and approving configurations and changes
- Managing customer-owned accounts, credentials, and data
- Maintaining backup, retention, recovery, and business-continuity requirements unless otherwise agreed in writing
Specific security responsibilities should be documented in the applicable contract or statement of work.
Incident Response
We maintain processes intended to evaluate and respond to suspected security events involving systems or information under our control.
Depending on the circumstances, response activities may include:
- Initial assessment and containment
- Investigation of affected systems or information
- Remediation
- Documentation
- Coordination with relevant providers or customers
- Legally or contractually required notifications
The nature and timing of any notification will depend on the facts, applicable law, and contractual obligations.
Security Certifications
Unless expressly stated in a signed agreement or verified on this website, iAmaran does not represent that it is certified under a particular security or compliance framework.
Customer solutions may use platforms or providers that hold certifications such as SOC, ISO, PCI DSS, or other standards. A provider’s certification does not automatically certify iAmaran or every solution built using that provider.
Please contact us if your project requires a specific certification, audit report, data-processing agreement, security questionnaire, penetration test, or regulatory control.
Responsible Vulnerability Reporting
If you believe you have identified a security vulnerability affecting our public website or systems, please report it privately to contact@iamaran.com using the subject line: Security Vulnerability Report.
Please include:
- A description of the suspected vulnerability
- The affected page, URL, or system
- Steps necessary to reproduce the issue
- Potential impact
- Screenshots or technical details that do not expose personal or confidential information
- Your contact information
Please do not:
- Access, modify, download, delete, or disclose data that does not belong to you
- Disrupt website availability or performance
- Use denial-of-service testing, malware, social engineering, or physical attacks
- Test third-party systems that are outside our control
- Publicly disclose a suspected vulnerability before we have had a reasonable opportunity to investigate and address it
Submitting a report does not authorize testing, guarantee compensation, create an employment or contractual relationship, or establish a formal bug-bounty program.
Contact Us
iAmaran Technologies LLC
Dallas–Fort Worth Area, Texas, United States
Email: contact@iamaran.com
Website: https://www.iamaran.com