CapchaCloud 20 control themes — strong security practices and transparency. We do not guarantee legal or regulatory outcomes.
Each item links to a dedicated page. Deeper evidence packets and runbooks are shared through procurement when appropriate.
Also: Why CapchaCloud · Roadmap (public product direction) · Status & probes
Operator: Service Automations LLC · Effective May 15, 2026 · Single contact: support@serviceautomations.ai
Technical orientation for counsel and operators on the embed lead-capture path. Not legal advice.
If Lead program is incomplete or embed-program cannot load, the live widget.js shows a short operator footnote under the sign-in card (no silent failure) so merchants know to finish dashboard setup or fix allowlists.
Printable counsel review summary ·
Embed test harness (same-origin; requires allowlisted ?client_id=) ·
Operator repo: docs/COUNSEL-LEAD-PROGRAM-REVIEW-PACKET.md, docs/CONSENT-TCPA-PRODUCT-PLAN.md.
How we describe controls alongside common frameworks—without claiming certification.
What we operate vs. what you configure (domains, keys, BYOB, webhooks).
Binding processor terms + SCC references. Start with DPA summary for orientation.
Who we rely on and how we notify material changes.
Data classes and lifecycle—in principle and by configuration.
How preservation requests work alongside deletion.
Append-only operational logs and hash-chain tamper evidence.
TLS, platform crypto, BYOB; CMK roadmap.
Severity model and customer communication principles.
How we drill breaches and outages—cadence and scope.
Access reviews and production change discipline.
Phishing-resistant MFA and break-glass expectations.
Known-good settings, drift reduction, infrastructure-as-code.
Disclosure intake and remediation targets.
Dependencies, provenance, CycloneDX artifacts in CI.
Gates: review, scans, secrets hygiene, release discipline.
Third-party testing cadence and remediation tracking.
Cloudflare regions and roadmap for tenant pinning.
PR checklist: minimization, purpose, sensitive fields.
How we assemble audit artifacts—controls, logs, policies, exports.
Operate with counsel for jurisdictional requirements. Contact: serviceautomations.ai.