Liminal Framework LLC

Last updated September 2026

Working practices

Client-approved systems

Work can be performed within client-designated systems, portals, and approved environments. Unapproved tools are not introduced into a client workflow.

Data minimization

Only the information needed for the reporting scope is accessed or handled. Client data is not copied to personal storage, personal email, or unapproved devices.

Least-privilege access

Reporting-level or read-only access is used where appropriate. Administrative access is not required when narrower permissions are sufficient.

HIPAA-aware practices

Healthcare information is handled with minimum-necessary access and confidentiality practices, under client direction and applicable agreements.

Authorized automation

Automation is used only where the client permits it and within the boundaries of the approved system, data, and reporting scope.

Confidentiality commitments

Personnel work under confidentiality obligations, and we sign client NDAs and security addenda as part of onboarding.

Secure workspace habits

Screen privacy, device locking, current operating-system and browser updates, and encrypted connections are standard working practice.

Incident communication

If a suspected issue affects client data, we notify the client contact promptly and follow the reporting steps defined in the engagement.

What we do not claim

We describe our working practices honestly. Liminal Framework LLC does not currently claim any formal certification or accreditation, including SOC 2, ISO 27001, FedRAMP, or HIPAA certification. HIPAA does not provide a general certification for organizations, and Liminal does not claim to be a HIPAA compliance expert.

Where a contract requires specific controls, security documentation, training, or background screening, we will review the requirement and confirm in writing what we can meet before work begins.

Website data

This website collects only what you submit through our forms and is served over encrypted HTTPS. Client records are never transmitted through or stored on this site. See the Privacy Policy for details.

To report a suspected security issue with this website, email contact@liminalframeworkllc.com with the details and how to reproduce it. Please do not test in a way that disrupts the site or accesses data that is not yours.

Discussing your security requirements

Tell us the access model, systems, and handling requirements for your reporting data and we will confirm how the work would be performed.