1. Overview
Our security program combines managed infrastructure, authenticated access, restricted permissions, private customer records, change review, monitoring, and incident response. Controls are selected for the information and function involved. No system can eliminate every risk, so safeguards are reviewed and improved as the service changes.
2. Data protection
- The public website and supported service connections use encrypted transport.
- Application records are kept in managed data services with access restricted by business need.
- Service credentials and signing material are kept out of public customer interfaces.
- Payment information is handled through the payment service used for the transaction; Go Green records the business result and payment reference needed to support the account.
- Backups and recovery procedures are reviewed as part of service continuity planning.
3. Account access and permissions
Passwords are protected before storage. Sign-in, registration, and recovery requests are subject to abuse controls. After authentication, access is limited according to the person's relationship to the account and the specific record requested. Sensitive changes require the authorization appropriate to that action.
Customers and team members should use unique passwords, protect their devices, avoid sharing sign-in or property-access information, and report suspected unauthorized access promptly.
4. Private links and customer records
Certain estimates, proposals, invoices, signatures, visits, reviews, and preferences may be available through a private link. Those links are intended only for the recipient and should be handled like an account credential. Sensitive actions verify the link and the record it authorizes before applying a change. Contact us if a private link is sent to the wrong person or may have been exposed.
5. Security operations
- Selected security-sensitive and administrative actions are recorded for authorized review.
- Access, private-link, payment, and record-boundary behavior is tested during release verification.
- Dependencies, configuration, and reported vulnerabilities are reviewed and addressed according to risk.
- Access is removed or changed when a role, engagement, or business need ends.
- Service providers are evaluated in light of their function and the information involved.
6. Incident response
A suspected incident is assessed to determine the affected systems, information, people, and time period. Response may include containing access, preserving relevant records, correcting the cause, restoring service, and monitoring for recurrence. We notify affected people and authorities when the facts and applicable law require notice.
7. Report a vulnerability
Send a suspected security vulnerability to security@gogreenorganicclean.com. Include the affected page, a clear description, and safe reproduction steps. Do not include passwords, payment-card data, property-access information, or another person's private records.
Please do not use social engineering, denial-of-service testing, destructive testing, or access beyond what is necessary to describe the issue. Any safe-harbor or reward arrangement must be agreed in writing before testing.
8. Service photos
When photos are part of an agreed service or issue review, access is limited to the applicable customer, service professional, and authorized business personnel. Photos should avoid people, private papers, screens, medications, and unrelated personal property whenever reasonably possible. Public or marketing use requires separate permission.
9. Business confidentiality
Commercial customers with specific confidentiality requirements may request an agreement at legal@gogreenorganicclean.com. Availability and terms are confirmed for the particular engagement.
10. Contact
Security reports: security@gogreenorganicclean.com
Privacy questions: privacy@gogreenorganicclean.com
General support: (941) 271-7948
Our machine-readable disclosure contact is available at /.well-known/security.txt.
