Trust Center

Trust, security & privacy.

This page is maintained by Sirianni Digital to answer common security and privacy questions about siriannidigital.com and the engagements we run for client law firms. It describes our current practices and the platform capabilities we rely on. It is not an independent certification or audit.

Security is a shared responsibility. We describe what we operate; client firms remain responsible for their own systems, accounts, and confidential client data.

01

Access & authentication

The public website does not require an account. Internal tooling used by our team is protected with email-based authentication through our managed backend provider, with session tokens stored in the browser and validated server-side on every privileged request.

Administrative database operations run only from server-side code using credentials that are never exposed to the browser.

02

Hosting & platform

The site is built with TanStack Start and served from an edge runtime via Lovable's hosting platform. Application data and authentication are handled by a managed Postgres backend with row-level security enabled on user-data tables.

Traffic is served over HTTPS. We do not self-host servers.

03

Data we collect

From the public site we collect what visitors submit through the free visibility audit form (typically a name, firm, email, and the URL they want reviewed) and basic request metadata required to operate the site.

During client engagements we receive the public information needed to perform AI Engine Optimization work (firm details, practice areas, attorney bios, citations, public directory listings). We do not request client-confidential matter information.

04

Subprocessors & integrations

We rely on a small set of vendors to operate the website and deliver client work, including our hosting/database provider, our transactional email provider for audit delivery, and third-party AI assistants whose public outputs we monitor on behalf of clients. We will provide the current vendor list on request.

05

Cookies & analytics

The site uses only the cookies and local storage required to operate the site and, where applicable, to keep a signed-in session active. We do not sell visitor data.

06

Retention & deletion

Audit submissions are retained for as long as we are actively working with or following up with the requester. You can ask us to delete your submission at any time by emailing the address below.

07

Privacy requests

To access, correct, or delete information you have shared with us, email info@siriannidigital.com from the address on file. We respond within a reasonable timeframe.

08

Security & incident contact

To report a suspected security issue with this website, email info@siriannidigital.com with a description of the issue and steps to reproduce. Please give us a reasonable window to investigate before any public disclosure.

09

Compliance

Sirianni Digital is a marketing services company and is not a law firm. We do not claim SOC 2, ISO 27001, HIPAA, PCI, or GDPR certifications. Where a client engagement has specific contractual security requirements, those terms govern that engagement.