Golden Dorado

Trust and security

Last updated 6 October 2026

Golden Dorado LLC designs, builds and operates custom systems that run our clients' day-to-day work, often including quoting and billing. This page sets out how we host and protect those systems, written for the finance, IT, security and procurement teams who review a new vendor. Everything here describes how we operate today.

Live system status

The short version

  • Each client system runs in its own isolated environment, in the United States (AWS, Ohio region).
  • Data is encrypted in transit and at rest, every change is recorded in an audit trail, and access is by role.
  • Databases are backed up every night to separate, encrypted storage, and we rehearse restores.
  • Systems are checked every 5 minutes, with live results on our status page.
  • We notify clients within 72 hours of confirming an incident that affects their data.
  • Your data is yours. You can export it at any time, and it is deleted when our agreement ends.

1.Hosting and data location

Client systems run on Amazon Web Services in the us-east-2 region (Ohio, United States). Each client gets its own environment: a separate database, separate file storage and separate configuration. No database, storage or credentials are shared between clients.

LayerServiceLocation
ApplicationAWS Lambda behind Amazon API GatewayAWS us-east-2, Ohio
DatabasePostgreSQL, managed by SupabaseAWS us-east-2, Ohio
Files and backupsAmazon S3, encrypted and versionedAWS us-east-2, Ohio
System emailAmazon SES, signed with DKIMUnited States

Client data stays in the United States. We do not sell client data, use it for advertising, or use it to train AI models.

2.Security controls

3.Backups and recovery

Every client database is backed up automatically each night to separate, encrypted, versioned storage, and each backup is kept for 35 days. Each backup records the number of rows in every table, and our restore rehearsal loads a backup into an empty database and checks it row for row against that record. A failed backup alerts our team immediately.

All infrastructure is defined as code and kept in version control, so an environment can be rebuilt from scratch and then restored from its latest backup.

4.Monitoring and availability

Each hosted system is checked every 5 minutes. Two failed checks in a row alert our team, and error alarms watch the applications themselves. Current status and 90 days of history are public at status.golden-dorado.com. Availability and support response commitments are set out in each client's support agreement.

5.How changes are made

Every change is made in version control, released through a scripted, repeatable deployment, and followed by an automated end-to-end test of the live system. Changes a client requests are tracked from request to release, and releases are documented.

6.Our people and access

We are a small, senior team. Our lead engineer holds the AWS Certified Solutions Architect, Associate certification. Our staff access a client system only to operate, support or fix it, and access to our cloud accounts is recorded by AWS CloudTrail.

7.Certifications and assurance

Our systems run on providers that are independently audited:

Golden Dorado itself does not hold a SOC 2 report or an ISO certification today, and we will not suggest otherwise. In their place we complete your security questionnaire (your own, or a standard one such as CAIQ or SIG Lite), share the documents listed below, and walk your team through how a system is built and run.

8.Subprocessors

These companies process data on our behalf for the client systems we run. We give clients 30 days' notice before adding one.

CompanyPurposeLocation
Amazon Web Services, Inc.Hosting, file storage, backups, email delivery, monitoringUnited States (Ohio)
Supabase, Inc.Managed PostgreSQL databaseUnited States (AWS Ohio)
Stripe, Inc.Billing our own invoices: the client company's billing contact and payment details only, never client system dataUnited States
Microsoft or GoogleSingle sign-on, only when the client turns it on, under the client's own Microsoft 365 or Google accountThe client's own tenant

9.Incident response

We follow a written incident response plan. If we confirm a security incident affecting a client's data, we notify that client without undue delay and within 72 hours, keep them updated while we contain and fix it, and then provide a written report of the cause and the changes we made.

10.Reporting a vulnerability

If you believe you have found a security problem in golden-dorado.com or a system we run, email security@golden-dorado.com with enough detail for us to reproduce it. We acknowledge reports within 2 business days and keep you informed until it is resolved.

We will not pursue or support legal action against good-faith research that avoids privacy violations, data destruction and service disruption, stays within your own test accounts, and gives us reasonable time to fix the issue before disclosure. Do not access, change or keep other people's data, and do not run denial-of-service, spam or social-engineering tests. We do not offer payment for reports. Our contact details are also published in security.txt.

11.Documents for your review

Available on request to support@golden-dorado.com:

12.Company information

Golden Dorado LLC
An Arizona limited liability company
7252 N Central Ave, Phoenix, AZ 85020

General and vendor documents: support@golden-dorado.com
Security: security@golden-dorado.com

You can confirm our registration on the Arizona Corporation Commission's entity search.

Related: Terms of service, Acceptable use policy, Privacy policy.