A security page that overstates is a liability, not a credibility asset. Every statement below describes a control that is actually in place for the TryEntitle website and early sales process. Client delivery environments are scoped per engagement.
Data in transit and at rest
- The public website at https://tryentitle.com is served over HTTPS / TLS via our host, Vercel.
- Booking data submitted through Calendly is transmitted to Calendly over TLS and stored in Calendly’s systems under Calendly’s security controls.
- TryEntitle does not store client production databases on this marketing website. Engagement workspaces and document stores are provisioned per client and documented in that engagement’s paperwork.
Access control
- Access to TryEntitle business systems used for sales and delivery is limited to people who need it for their role.
- Access is revoked when a person leaves the engagement or the company.
- Multi-factor authentication is enabled on TryEntitle-controlled accounts that hold client or prospect data wherever the provider supports it.
- Shared credentials for client systems are avoided; where a client requires a shared login, it is treated as a temporary exception and rotated or revoked when no longer needed.
Subprocessors
Website and early sales subprocessors currently in use:
| Subprocessor | Role |
|---|---|
| Calendly | Scheduling and booking |
| Vercel | Website hosting and content delivery |
This list matches the processor table in the Privacy Policy and Annex 2 of the Data Processing Agreement. Additional delivery subprocessors for a paid engagement are disclosed in that engagement’s DPA annex.
Human review and handling
TryEntitle’s services often keep a person in the loop for exceptions and judgment calls. For client work:
- working documents are stored only in systems agreed for that engagement;
- exception review is performed by named TryEntitle personnel (or client-named reviewers) with access limited to what the workflow requires; and
- working data is retained only as long as the engagement and DPA allow, then deleted or returned.
The marketing site itself does not host client case files.
Vulnerability reporting
If you believe you have found a security issue affecting tryentitle.com or a TryEntitle-operated system, email security@tryentitle.com.
Please include enough detail for us to reproduce the issue. We will acknowledge reports within 5 business days and keep you updated as we investigate. Do not access data that is not yours, and do not degrade the availability of our services while testing.
Incident response
If TryEntitle becomes aware of a personal data breach affecting personal data we process for a client, we will notify the affected client without undue delay and, where feasible, within 72 hours, consistent with our Data Processing Agreement. Notification will include the facts then known and the steps we are taking, with follow-up as the investigation develops.
Contact
Security reports and questions: security@tryentitle.com
Privacy requests: privacy@tryentitle.com
General enquiries: hello@tryentitle.com
