Northmrk

Security

Security contact: Jake Runyon, Founder & CTO — jake@northmrk.com.

Jake Runyon is the founder and the person responsible for security at Northmrk. He receives vulnerability reports, incident notices, and misuse alerts, and he can act on them.

Report a vulnerability

If you find a security issue in a Northmrk system, email jake@northmrk.com. Include what you found, where, and how to reproduce it. Do not access data that is not yours, and do not disrupt production systems.

We acknowledge reports, investigate, and tell you when the issue is resolved. Good-faith research is welcome. We do not run a paid bug bounty.

Incidents

If you believe a Northmrk system has been compromised, put “Incident” in the subject line. We treat that as a priority: contain, revoke access, and notify anyone who needs to know.

When we use a third-party model grant, Jake Runyon is the named contact for security and misuse alerts. We report suspected breach or misuse of that access within 72 hours — 24 hours for a security incident — investigate flags within 48 hours, and notify the provider if our security contact, ownership, or headquarters changes.

How we run it

  • One named owner for security and incidents: Jake Runyon.
  • Access limited to people who need it. Shared logins are not used on production systems.
  • Multi-factor authentication on accounts that can reach production or model workspaces.
  • Secrets kept in a secrets manager, not in source or chat.
  • Traffic to our systems is encrypted in transit.
  • Sensitive client numbers are collected through a one-time vault. They are not sent in email or SMS, and they are deleted after they are used.

Company

Northmrk is a Technology & Operations firm in Tampa, FL. We build and operate the software used in our own work and by our clients.

512 N. Franklin St. Tampa, FL 33602

General: tech@northmrk.com

Updated October 7, 2026

Northmrk