Preamble
Black Swan Ventures Group LLC (the "Company") designs and installs systems which touch client relationship records, electronic mail infrastructure, recordings of telephone communications, and prospect data. This instrument states the Company's security posture, its undertakings in the event of an incident, and the procedure by which a vulnerability is to be reported.
It is drafted upon the principle that an overstated security disclosure is itself a misrepresentation, and that a small and focused firm is better served by an accurate account of what it does than by an aspirational account of what it does not.
Every matter marked [CONFIRM] must be verified as true before publication. No control is to be published which is not in fact operated.
1. Scope
This instrument covers the website located at cashflowpositive.ai, the systems operated by the Company in the delivery of its services, and client data processed in the course of an engagement. It does not extend to platforms owned by the client, responsibility for which remains the client's.
2. Organisational Measures
2.1 Access upon necessity. Access to client systems and data is granted only to personnel having an operational need for it.
2.2 Multi-factor authentication is mandatory upon every administrative account, every electronic mail account, and every platform operated by the Company. [CONFIRM]
2.3 Credential hygiene. Credentials are held within a dedicated password manager and are in no circumstances recorded in plain text within documents, messages, or electronic mail. [CONFIRM: identify the manager]
2.4 Least privilege in client environments. The Company requests the narrowest permission set consistent with delivery, prefers scoped application programming interface keys to full account access, and requires that clients revoke its access upon the conclusion of an engagement.
2.5 Personnel and contractors execute obligations of confidence and of data protection prior to the grant of any access.
2.6 Vendor diligence. Sub-processors are selected with regard to their security posture and are bound by written data processing agreements. See the Sub-processor Register and the Data Processing Addendum.
2.7 Review of access rights is conducted not less frequently than [CONFIRM: quarterly] and upon the conclusion of every engagement.
3. Technical Measures
| Control | Implementation |
|---|---|
| Encryption in transit | Transport Layer Security version 1.2 or higher across the website, application programming interfaces, and administrative interfaces; HTTP Strict Transport Security enabled |
| Encryption at rest | As afforded by the Company's hosting, storage, and database providers, employing industry-standard algorithms |
| Perimeter | Managed edge provider with distributed denial-of-service mitigation and web application firewall [CONFIRM] |
| Segregation | Client data logically separated by engagement |
| Backup | [CONFIRM: frequency, retention, and whether restoration is tested] |
| Logging | Administrative and authentication events logged and retained for [CONFIRM: 12 months] |
| Patching | Dependencies and platforms maintained current; critical security patches applied within [CONFIRM: 7 days] of availability |
| Endpoint | Full-disk encryption and automatic screen lock upon every device employed for client work [CONFIRM] |
4. Controls Specific to Artificial Intelligence
The Company's deliverables involve artificial intelligence systems. The Company accordingly:
(a) employs the business or enterprise tier of model providers wherever an undertaking against training upon customer inputs is available, and configures that setting;
(b) refrains from submitting special categories of personal data, credentials, or regulated records into third-party model application programming interfaces;
(c) discloses within each engagement the identity of every model provider processing client data, and records the same in the Sub-processor Register;
(d) applies review by a natural person to output prior to its reaching a production system;
(e) designs against prompt injection where a system ingests untrusted content, and states any residual risk to the client upon handover.
5. Recording Devices and Call Capture
5.1 The Company employs dedicated capture hardware, including devices supplied by Plaud, together with cloud telephony, for the recording and transcription of calls.
5.2 Such devices and services are configured so that: recording is preceded by an audible announcement; recordings are transferred over encrypted channels; recordings are retained in accordance with clause 7 of the Privacy Policy; and access is confined to personnel having an operational need.
5.3 The lawful basis, the consent regime applicable in all-party consent jurisdictions, and the data subject's rights in respect of recordings are set out at clause 8 of the Privacy Policy and in the Cold Outreach & Communications Policy.
6. Matters Not Claimed
The following are stated expressly, in order that no client should draw an inference from silence:
(a) The Company holds no SOC 2, ISO/IEC 27001, HIPAA, or PCI-DSS certification. [CONFIRM, to be amended upon any such certification being obtained.]
(b) The Company does not store complete payment card particulars; payments are processed by a provider maintaining its own certification under the Payment Card Industry Data Security Standard.
(c) The Company does not operate a security operations centre.
(d) The Company does not presently commission routine third-party penetration testing. [CONFIRM]
(e) No system of information security is impregnable. The Company gives no warranty that its measures will prevent every compromise.
7. Incident Response
Upon becoming aware of a security incident affecting personal data or client systems, the Company undertakes as follows:
| Step | Undertaking |
|---|---|
| Containment | Immediately upon discovery |
| Assessment of scope and impact | Within 24 hours |
| Notification of affected clients | Without undue delay, and in any event within 48 hours of confirming that an incident affects that client's data |
| Notification of supervisory authority (Article 33 GDPR) | Within 72 hours of becoming aware, where the breach is likely to result in a risk to natural persons |
| Notification of data subjects (Article 34 GDPR) | Without undue delay, where the risk is high |
| Notification under State breach statutes | In accordance with the applicable statute |
| Written post-incident report | Within 30 days of resolution |
Where the Company acts as processor, it notifies the client without undue delay and supports that client's own obligations of notification. It does not notify the client's supervisory authority or data subjects on that client's behalf save upon written instruction.
8. Vulnerability Disclosure
8.1 The Company welcomes good-faith security research and shall not pursue legal proceedings against a researcher observing this clause.
8.2 Reporting. Reports are to be addressed to mgmt@blackswanventuresgroup.com, the subject line being prefixed with the word SECURITY. A public key is available upon request.
8.3 Contents of a report. The affected uniform resource locator or system; steps by which the issue may be reproduced; an assessment of impact; and any proof of concept.
8.4 Undertakings of the Company.
| Stage | Period |
|---|---|
| Acknowledgement of receipt | 3 business days |
| Initial triage and assessment of severity | 10 business days |
| Status reports | Every 14 days until resolution |
| Remediation, critical | 7 days |
| Remediation, high | 30 days |
| Remediation, medium and low | 90 days |
| Public credit, where desired | Upon resolution |
8.5 Rules of engagement. A researcher shall not: access, alter, or delete data not belonging to that researcher; conduct denial-of-service or volumetric testing; employ social engineering, phishing, or physical intrusion against the Company's personnel or premises; test third-party services merely employed by the Company; or disclose the issue publicly before remediation or the expiry of ninety days, whichever first occurs.
8.6 The Company does not presently operate a paid bounty. [CONFIRM] Recognition is offered in lieu.
9. Responsibilities of the Client
Security is a shared undertaking. The client is responsible for: the security of its own platforms and accounts; the enabling of multi-factor authentication upon accounts to which the Company is granted access; the revocation of that access upon the conclusion of the engagement; the review and approval of artificial intelligence systems prior to deployment in production; and the lawful processing of data within systems delivered to it.
10. The Company
Black Swan Ventures Group LLC
30 N Gould Street, Ste N, Sheridan, Wyoming 82801, United States of America
mgmt@blackswanventuresgroup.com · +1 872-375-3144
Security reports: subject line prefixed SECURITY. Breach and privacy enquiries: prefixed PRIVACY.
Schedule I, Machine-Readable Security Contact
The following is published at /.well-known/security.txt. Scanners and researchers look for it, and its presence is a credible signal in enterprise vendor review.
Contact: mailto:mgmt@blackswanventuresgroup.com Contact: tel:+18723753144 Expires: 2027-08-01T00:00:00.000Z Policy: https://cashflowpositive.ai/security Preferred-Languages: en Canonical: https://cashflowpositive.ai/.well-known/security.txt
Schedule II, Trust Indicators (specification for the Website)
A row of security indicators may be displayed upon this page and upon the AI Concierge application page. Each indicator must correspond to a control actually operated, and each must link to the clause of this instrument which substantiates it. An indicator representing a certification not held is a misrepresentation and is prohibited.
Permitted indicators, upon confirmation of the underlying control:
| Indicator | Substantiated by | Permitted only if |
|---|---|---|
| TLS 1.2+ Encrypted | Clause 3 | Verified upon the live certificate |
| GDPR-Aligned Processing | Privacy Policy, DPA | The DPA is published and offered |
| Data Processing Agreement Available | DPA | True upon publication |
| Multi-Factor Authentication Enforced | Clause 2.2 | Enforced upon every account without exception |
| Sub-processor Register Published | Sub-processors | The register is complete and accurate |
| 48-Hour Breach Notification | Clause 7 | The undertaking is given, as it is |
| Vulnerability Disclosure Programme | Clause 8 | The address is monitored |
| Encrypted Call Capture | Clause 5 | Verified upon the Plaud and telephony configuration |
| No Model Training on Client Data | Clause 4(a) | Verified upon each provider's account settings |
Prohibited unless and until obtained: SOC 2, ISO 27001, HIPAA, PCI-DSS, "bank-grade", "military-grade", "enterprise-grade security", and every analogous formulation incapable of substantiation. Clause 6 exists precisely so that the absence of these may be stated openly rather than implied away.
Correspondence
Black Swan Ventures Group LLC30 N Gould Street, Ste N
Sheridan, Wyoming 82801
United States of America
mgmt@blackswanventuresgroup.com
+1 872-375-3144
Related notices