Innovation Starts with Trust.
At Above Promotions, we believe that true impact is built on a foundation of integrity, security, and ethical partnership. It’s not simply what we deliver in marketing and technology, but how we deliver it.
Scope of Applicability
This Trust Center describes Above Promotions LLC’s general security, privacy, and ethical posture. Specific contractual obligations, service levels, performance commitments, or data handling practices may vary based on the nature of the engagement, membership tier, or applicable written agreement. This Trust Center is provided for transparency and informational purposes only and does not create contractual obligations unless expressly incorporated into a written agreement.
We are driven to be a force for good for our clients and their communities. This means we design our Innovation Lab technologies, from AI to MarTech, intentionally and responsibly, ensuring they serve to amplify your brand’s positive message.
Grounded by our comprehensive Code of Ethics and a commitment to the NIST Cybersecurity Framework, we innovate to achieve unparalleled results while rigorously protecting client confidentiality and privacy. We work hard every day to be transparent, predictable, and accountable, solidifying the trust that allows us to operate at the intersection of innovation and impact.
Our Foundation of Trust: Security, Ethics, and Enterprise Readiness.
We build and implement advanced marketing technology and deliver communications training that organizations rely on. This Trust Center explains how we protect data, operate responsibly (including AI), and meet the rigorous security and compliance expectations of enterprise, government, and public-sector buyers.
Our tagline: Above Promotions, where innovation meets impact. This is evidence of our impact.
Last reviewed and updated: January 26, 2026
1. Security: Enterprise-Grade Protection
Our security posture is not just a checklist; it’s a strategic commitment built on the NIST Cybersecurity Framework (CSF). This standard ensures we proactively manage risk across all our divisions.
Owner: Technology Manager Contact: [email protected]
| Feature | Technical Detail | Plain-English Summary |
| Framework | NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover). Regularly audited. | We constantly scan for weaknesses. In the event of a critical incident, we have a clear and tested plan to contain it, and we will notify impacted clients within 72 hours of its discovery. |
| Vulnerability & IR | Vulnerability Management: Critical findings remediated within 7 days (SLA). Incident Response (IR) Plan: Established roles and communication protocols. | We are prepared for the unexpected. We can restore our core services within hours, ensuring minimal data loss and guaranteeing project continuity. |
| Business Continuity | Nightly encrypted backups, cross-region replication. Recovery Time Objective (RTO): 4 hours. Recovery Point Objective (RPO): 2 hours. | We are prepared for the unexpected. We can restore our core services within hours and ensure minimal data loss, guaranteeing project continuity. |
| Availability Target | Our expected platform uptime (excluding scheduled maintenance) is 99%. | Our commitment to system reliability means you can count on us to be available when you need us. |
Security Contact & Vulnerability Disclosure: We welcome security researcher collaboration and promote safe disclosure. We publish a security.txt file at https://www.abovepromotions.com/.well-known/security.txt which contains our current contact details and policy link for responsible vulnerability reporting.
2. Responsible AI: Ethical Innovation
Responsible AI Scope
This section describes internal principles and governance practices related to artificial intelligence. It does not create guarantees or contractual obligations.
Our Innovation Lab utilizes Machine Learning (ML) and Artificial Intelligence (AI) to deliver cutting-edge solutions, always governed by our Code of Ethics and a commitment to transparency.
Strategic Focus: Trustworthy AI that drives ethical results, not risk.
| Principle | Our Commitment (Code of Ethics Integration) | Plain-English Summary |
| Confidentiality & Privacy | No customer content is used for general model training by default. Any client-specific fine-tuning requires explicit consent via the SOW. | Your proprietary data is yours—we don’t use it to train the AI we use for other clients. |
| Transparency & Accountability | Outputs generated or heavily influenced by AI (e.g., Google Gemini, Notebook LLM) are marked with disclosure badges. All content is subject to a mandatory human-override and review process. | You will always know when AI has been used, and a skilled AP professional is always responsible for the final quality and accuracy. |
| Fairness & Non-Discrimination | We adhere to our Human Rights Policy to actively mitigate bias in content generation, ensuring outputs are respectful and equitable. | We actively work to ensure our AI tools do not perpetuate bias or create discriminatory content. |
AI-assisted tools may process client-provided materials solely to deliver requested services. Client content is not incorporated into shared or external model training without explicit written consent. Final responsibility for review, approval, and use of AI-assisted outputs remains with the client.
3. Compliance & Certifications
Our ethical framework is the foundation of our entire operation, ensuring we meet all regulatory, ethical, and contractual obligations.
- Ethical Core (Code of Ethics): Our firm operates on the principles of Integrity, Confidentiality, and Compliance. This ensures client materials and credentials are handled under strict Confidentiality rules, enforced during the AP Internal New Client Onboarding Process.
- Human Rights: We are committed to our Human Rights Policy, ensuring fair labor practices and non-discrimination across our operations.
- Regulatory Alignment: Our NIST-based security program is designed to align with security best practices for GDPR and PCI DSS.
Data Processing Addendum (DPA) & Subprocessors
We rely on carefully vetted third parties (Subprocessors) to provide specialized services.
- Contracting: Standard Master Service Agreements (MSA) and a comprehensive Data Processing Addendum (DPA) are provided to all clients.
- Breach Notification: We contractually guarantee notification of any material data breach to the affected client within 72 hours.
- Subprocessor List: The complete list of third-party subprocessors who handle or store client data is considered proprietary and is available for review under NDA in our Document Room.
4. Reliability, Business Continuity & Status
We view reliability as a critical component of client service, ensuring high availability for all platforms used in campaign execution and client collaboration.
- Accessibility: We are committed to inclusive design, striving for WCAG 2.1 AA compliance across all client-facing digital products and training materials. Accessibility concerns should be reported through designated contact channels to allow prompt investigation and remediation.
- Live Status: You can check the live status and operational updates of our primary services, including the Innovation Lab and Client Portal.
Availability targets reflect internal performance objectives and do not constitute service-level guarantees unless expressly stated in a written agreement.
5. Document Room (For Due Diligence)
For enterprise, federal, and defense clients requiring formal due diligence, the following documents are available under a Non-Disclosure Agreement (NDA):
- Subprocessor List & Changelog
- SOC 2 Type II Report (when available)
- External Penetration Test Executive Summary
- Detailed Control Mappings (NIST CSF, ISO 27001)
- Business Continuity Plan & Incident Response Policy Summaries
Ready to engage? Our commitment to the NIST framework and ethical AI is your assurance of a secure partnership.
Contact our Sales or Procurement team to request access to the Document Room.