Security & Data Handling
Last Updated: August 19, 2026
This page documents Cold Creek's security posture, data handling architecture, and coordinated vulnerability disclosure process. It is intended for enterprise IT security reviewers, procurement teams, and security researchers. Cold Creek is operated by Ironclad Digital LLC, which does business online under the Ironclad Integrity brand (ironcladintegrity.com); Ironclad Digital LLC is the entity named throughout this page and in any contract.
1. Data Handling Architecture
Cold Creek's simulator stores all game state, including shift results, settings, and progress, exclusively in your own browser's localStorage. This data is never transmitted to Ironclad Digital LLC's servers or to any third party. There is no backend database, no user accounts, and no server-side session storage associated with simulator activity. The outbound connections this site makes are to Vercel's infrastructure for the page itself; to Sentry for error reporting if a page throws a JavaScript error (stack trace and page URL only, with cookies, headers, and user identifiers stripped before send); and, if you submit the contact form on the /teams page, to FormSubmit.co for email forwarding. None of these connections involves your simulator game data: game state never leaves localStorage. The practical consequence: Ironclad Digital LLC cannot be compelled to produce, disclose, or breach your simulator data because we do not hold it.
2. Transport Security
- TLS in transit: All page loads and form submissions use HTTPS (HSTS enforced via
Strict-Transport-Security: max-age=31536000; includeSubDomains). - Content Security Policy: Strict CSP including frame-ancestors limited to Vercel preview domains.
- Common headers: X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy disabling camera, microphone, and geolocation. The legacy X-XSS-Protection header is explicitly set to 0 per current guidance, since the browser auditor it enabled has itself been a vulnerability source.
3. Sub-Processors
| Provider | Purpose | Data Shared |
|---|---|---|
| Vercel Inc. | Website hosting, edge delivery, and anonymized analytics | IP address (anonymized for analytics), page views, Web Vitals metrics |
| FormSubmit.co | Email forwarding for /teams contact form submissions only | Form fields you submit (name, work email, company, role, message) |
| Functional Software, Inc. (Sentry) | JavaScript error reporting, so site and simulator errors get found and fixed | Error stack traces, page URL (query strings stripped), browser and OS version, IP address at the network layer. Cookies, headers, and user identifiers are stripped before send. No game data, no form data. |
No other third-party processors handle Cold Creek user data. This list is current as of the Last Updated date above. We commit to updating this page at least 30 days before adding any new sub-processor that handles user data. One correction in that spirit: Sentry error reporting went live on August 5, 2026 and this page was updated after the fact rather than 30 days ahead. That was a process miss on our side, documented here instead of papered over.
4. Infrastructure Compliance
Cold Creek's infrastructure provider, Vercel holds SOC 2 Type II certification. Ironclad Digital LLC operates on top of Vercel's platform but does not separately maintain SOC 2 certification at this time. Enterprise customers requiring additional security certifications should reach out via /teams to discuss specific requirements.
5. Data Processing Agreement (DPA)
Enterprise customers may request a Data Processing Agreement by emailing hello@ironcladintegrity.com with the subject line "DPA Request." We respond within five business days.
6. Coordinated Vulnerability Disclosure
If you have identified a security vulnerability in Cold Creek, please report it to hello@ironcladintegrity.com. We commit to:
- Acknowledge receipt of valid reports within five business days.
- Provide a preliminary assessment within ten business days.
- Coordinate disclosure timing with the reporter.
- Acknowledge researchers who report valid findings (see Acknowledgments below).
Our machine-readable security contact follows RFC 9116 and is available at /.well-known/security.txt.
Please do not attempt denial-of-service, do not access user data that does not belong to you, and do not test against any third-party service we depend on (Vercel, FormSubmit). Reports involving social engineering of Ironclad Digital LLC personnel are out of scope.
7. Acknowledgments
We will acknowledge researchers who report valid findings to hello@ironcladintegrity.com. No reports have been received as of the Last Updated date.
8. Roadmap
The following items are on Ironclad Digital LLC's security roadmap for enterprise customers and are not currently available. Contact us if any of these are a requirement for your evaluation:
- Single sign-on (SSO) integration via SAML 2.0 or OIDC.
- Audit logging for enterprise customer activity.
- SOC 2 Type II certification (Ironclad Digital LLC, in addition to Vercel's existing certification).
None of these items have a published delivery timeline.
9. Contact
- Security email: hello@ironcladintegrity.com
- Subject line for vulnerability reports: "Security Report"
- Subject line for DPA requests: "DPA Request"
- RFC 9116 machine-readable: /.well-known/security.txt