Security Posture Statement

Phantone.fm Security Posture

Effective August 13, 2026 · Midtown West LLC d/b/a Phantone.fm

01Company and scope

Phantone.fm is a product of Midtown West LLC, a California limited liability company with its principal place of business at 705 Gold Lake Dr Suite 250, Folsom CA 95630 ("Phantone", "we", "us"). This statement covers the Phantone audio-watermarking SaaS, associated APIs, dashboards, and webhook delivery infrastructure operated by Midtown West LLC.

02Governance

Phantone operates a founder-led security program owned by Matthew Loughran, EMBA, Founder of Midtown West LLC. Information security, privacy, and acceptable-use policies are reviewed at least annually and after any material change. Security and privacy awareness training is required for all personnel with production access; the current program targets initial training within 30 days of hire and refresher training at least annually.

03Data classification

Phantone classifies data as Public, Internal, Confidential, or Restricted. Customer audio fingerprints, attribution events, and end-user identifiers are treated as Restricted and receive the highest level of technical and contractual protection.

04Encryption

All Restricted and Confidential data is encrypted at rest using AES-256 across the database, object storage, and backups. All traffic between clients, the Phantone application, the Phantone API, and outbound webhook receivers is encrypted in transit using TLS 1.2 or higher. Encryption keys are held in a managed KMS with documented rotation policy.

05Access control

Phantone enforces least-privilege role-based access control. Production access requires SAML SSO with enforced MFA, is reviewed quarterly, and is automatically deprovisioned upon role change or separation. Customer-facing tenancy uses six application roles (Owner, Admin, Operator, Analyst, Auditor, Viewer) backed by row-level security at the database layer.

06Network security

Production services run inside a private VPC with no public database exposure. Edge traffic is protected by a Web Application Firewall and DDoS mitigation. Per-workspace IP allowlisting is available for customers who require it for API and dashboard access.

07Application security

Phantone follows a documented secure SDLC: mandatory peer code review, dependency scanning in CI, secret scanning, and static analysis on every pull request. Phantone plans to commission independent third-party penetration testing at least annually as the product enters general availability. Reproducible vulnerability reports may be submitted to security@phantone.fm.

08Vulnerability management

Phantone targets remediation of Critical findings within 7 days, High within 30 days, and Medium within 90 days from the date of confirmed reproduction. Operating systems and managed services are patched on the provider's published cadence.

09Logging and monitoring

Application, infrastructure, and audit logs are centralized. Audit logs are retained up to 365 days for security and compliance purposes. On-call coverage targets 24/7 response for availability, error-rate, and security signals as the platform scales into general availability.

10Backups and disaster recovery

Customer databases are backed up daily with point-in-time recovery available for up to 7 days. Phantone targets a 4-hour Recovery Time Objective (RTO) and a 1-hour Recovery Point Objective (RPO) for the production service. Restore procedures are tested on a documented cadence, with a target of at least quarterly restore validation.

11Incident response

Phantone maintains a documented Incident Response Plan. We will notify affected customers without undue delay and in any event within 72 hours of confirming a Personal Data Breach affecting their data, consistent with our Data Processing Agreement. A written postmortem is provided within 10 business days of resolution.

12Sub-processors

Phantone uses a documented list of sub-processors for cloud hosting, managed Postgres, transactional email, error monitoring, support helpdesk, and payment processing. All sub-processors are contractually bound to obligations equivalent to those Phantone owes its customers. Customers receive 30 days' prior notice of a new sub-processor that processes their personal data.

13Personnel security

All Midtown West LLC personnel sign confidentiality and acceptable-use agreements at hire. Phantone's program provides for background checks where permitted by applicable law and required by role. Access to production systems is removed within 24 hours of separation.

14Physical security

Phantone does not operate physical data centers. Physical security controls are inherited from our infrastructure providers, which maintain SOC 2 Type 2 and ISO 27001 attestations covering perimeter, access, environmental, and media-handling controls.

15Business continuity

Phantone maintains a documented Business Continuity Plan covering personnel availability, infrastructure failure, and sub-processor outage scenarios. The plan is reviewed and tested at least annually.

16Compliance frameworks

Phantone's SOC 2 Type 2 audit for the product is in progress (Phase 1 — policies and controls matrix complete). The underlying infrastructure providers are SOC 2 Type 2 and ISO 27001 attested. Phantone is aligned with GDPR / UK GDPR and CCPA / CPRA. HIPAA is not in scope. PCI DSS scope is minimized via a tokenized third-party payment processor; Phantone does not store cardholder data.

17Customer responsibilities

  • Configure SSO and enforce MFA for all workspace members.
  • Promptly offboard departing users from their workspace.
  • Rotate API keys at the frequency required by their internal policy and on any suspected compromise.
  • Keep webhook receiver endpoints over HTTPS and validate Phantone signatures on every request.

18Contact

Security, privacy, and compliance inquiries: compliance@phantone.fm. Postal mail: Midtown West LLC, 705 Gold Lake Dr Suite 250, Folsom CA 95630.

Signed
Matthew Loughran

Matthew Loughran, EMBA

Founder, Midtown West LLC d/b/a Phantone.fm

705 Gold Lake Dr Suite 250, Folsom CA 95630 · compliance@phantone.fm

Effective: August 13, 2026