Security
How Carlton Brooke protects information.
Carlton Brooke is an AI and business-systems consultancy. Security is treated as part of professional work—not as a product slogan. This page distinguishes how this website handles inquiries from the principles applied when an engagement involves systems, data, integrations, hosting, or AI.
This website
The public website is for information and inquiries. Contact form submissions are used to send an email notification to Carlton Brooke LLC through a trusted email provider. Those submissions are not stored in a client systems platform as part of this website.
Consulting engagements
When work involves a client’s systems, information, integrations, hosted environments, or AI capabilities, we design access and handling around the client’s context. Client information should not be mixed with another client’s information. People should receive only the access needed to do the work.
Least privilege
Access should be limited to what the work requires. Permissions should be explicit and understandable. Administration of infrastructure, where it is part of an engagement, is kept separate from day-to-day use of a client’s own systems.
Sensitive information
We design work to avoid unnecessary copying of regulated or highly sensitive information. Specialized providers may be used for payments, messaging, authentication, or other infrastructure where that is appropriate.
Review and improvement
Where we help operate or implement systems, significant activity should be reviewable so problems can be traced and practices can improve. Security expectations evolve with the work, the data involved, and the client’s environment.
