Skip to content
OC Security Audit
  • Home
  • Cybersecurity
    • Industries We Serve
    • Managed IT
    • Internal Network Security for Business Networks
    • Microsoft Azure Security
    • Business Continuity & DR
    • Microsoft 365 Email Security
    • Firewall Security Assessment
      • Firewall Security Checklist
    • Threat Detection
    • AI-Powered Cybersecurity
    • Automated Incident Response
    • Risk Management
    • Endpoint Security
  • Security Audit
    • Network Vulnerability Assessment
    • Cybersecurity Risk Assessment
    • Internal Security Audit
      • Router and Switch Security Audit Checklist
    • External Security Audit Services in Irvine & Orange County
    • Microsoft Office 365 Audit
      • Microsoft 365 Copilot Security Assessment
    • Azure Cloud Security Audit Services
      • Microsoft Entra ID Security Audit
    • Firewall Security Audit
  • Compliance
    • HIPAA
      • Are You HIPAA Compliant?
      • Business Leadership Role
      • HIPAA Risk Assessment
      • Security Rule Matrix
      • Free HIPAA Checklist
      • Free HIPAA Assessment
    • PCI-DSS Compliance
      • PCI-DSS technical assessment
      • Free PCI-DSS Consultation
    • SOC 2 Compliance
    • NIST Cybersecurity Framework
    • ISO/IEC 27000 Compliance
      • ISO 27001 Readiness Checklist and Annex A Controls
    • CMMC 2.0 Readiness
    • Cyber Insurance Assessment
      • Cyber Insurance Checklist
    • IRS WISP Compliance
  • vCISO
    • Security Governance
    • Risk Assessment Services
    • Vulnerability Management
    • IT security consulting
    • Incident Response & Digital Forensics
  • Free Tools
    • Business Technology Risk Navigator
    • Free Cybersecurity & IT Readiness Assessment Wizard
    • Cloud Security Readiness Assessment Wizard
      • Microsoft 365 Security
      • Azure Cloud Security
      • Email Security & Compromise
      • AWS Security Readiness Assessment
      • Google Workspace Security Assessment
      • Microsoft 365 Secure Score Explainer
    • Compliance Readiness Assessment Wizard
      • HIPAA Security Readiness
      • PCI DSS Readiness
      • IRS WISP Compliance
    • General Cybersecurity Risk
      • Backup & Disaster Recovery
      • Firewall Configuration Risk
      • Remote Workforce Security
      • Executive Cyber Risk
      • Ransomware Resilience
      • Cyber Incident Response
      • Server Security Hardening
      • Zero Trust Assessment
      • Endpoint Security and EDR
      • Wi-Fi and Guest Network
      • Identity & Access Management
      • Privileged Account Security
      • Vulnerability Management
      • Virtualization Security
      • Website Security & Privacy Risk Check
      • Active Directory Security Audit
      • Incident Response Tabletop Generator
      • Vendor Risk Assessment Tool
      • Ransomware Recovery Cost Estimator
      • Cyber Insurance Readiness Tool
      • Board-Level Cyber Risk Scorecard
    • Free CISO Tools
      • CISO Daily Operations Checklist
      • Cybersecurity Roadmap and Priorities Assessment
      • Data Protection and Sensitive Information Security Assessment
      • Security Awareness Program Assessment
      • Compliance Readiness Selector Assessment
      • Executive Cyber Risk Scorecard Assessment
      • Incident Response Tabletop Readiness Assessment
      • Vendor and Third-Party Risk Assessment
      • Security Policy and Standards Gap Assessment
      • Cyber Risk Management Assessment
      • Cybersecurity Governance Readiness Assessment
    • Free Internal Audit Tools
      • Internal Network Security Audit Tool – V2
    • Free External Audit Tools
      • External Security Audit Tool – V2
    • Network Asset Discovery Tool
    • Secure Your Network
    • Security Implementation Guides for Administrators
  • Contact
    • Orange County Free Onsite Cybersecurity Consultation
    • Schedule a Cybersecurity Consultation
    • Irvine Cybersecurity
    • Industries
      • CPA Firms & Tax Preparers
      • Healthcare Clinics
      • Dental Offices
      • Law Firms
      • Manufacturing Companies
      • Construction Companies
      • Engineering Firms
      • Real Estate Companies
      • Nonprofit Organizations
      • Cyber Insurance Readiness
      • Independent Security Audit for MSP Clients
    • MSP and MSSP Partner Program

Your privacy, choices, and security matter

This Privacy Policy explains how OC Security Audit, managed by Ali Hassani, collects, uses, protects, and shares information when you visit this website, request information, submit a form, or interact with our cybersecurity, compliance, risk assessment, and vCISO resources.

Effective: July 14, 2026Applies to ocsecurityaudit.comCalifornia-focused notice

This notice is written to provide clear, practical information about our website practices. It does not replace legal advice and does not describe data handling for a separately documented client engagement, which may be governed by an agreement, statement of work, confidentiality terms, or other engagement-specific requirements.

1. Information we collect

Information you provide

We may collect information you choose to submit, such as your name, business name, email address, telephone number, preferred contact method, service interests, consultation details, and the contents of a message. Please do not submit passwords, authentication codes, payment-card data, protected health information, government identifiers, sensitive security configurations, vulnerability details, or confidential client data through a public website form.

Website and device information

When you use the website, our hosting, security, analytics, advertising, and consent-management technologies may process limited technical information. Depending on your choices and configuration, this can include IP address, browser and device type, operating system, referring page, pages viewed, approximate region, timestamps, interactions with website features, diagnostic events, and cookie or similar identifiers.

Security information

Security controls may process IP addresses, request details, login attempts, suspicious behavior, and related technical data to detect abuse, protect the website, investigate security events, and maintain service availability.

2. How we use information

We use information for legitimate business and operational purposes, including to:

  • Respond to inquiries, consultation requests, and service questions.
  • Provide, maintain, secure, and troubleshoot the website.
  • Understand site performance and improve content, usability, and visitor experience.
  • Measure outreach and advertising effectiveness when permitted by your consent choices.
  • Prevent fraud, spam, malicious activity, and unauthorized access.
  • Maintain business records, fulfill contractual obligations, and comply with applicable law.
  • Establish, exercise, or defend legal claims.

3. Cookies, analytics, and advertising

The website may use essential technologies required for security, site operation, load balancing, preference storage, and consent management. With the choices offered through our consent banner, optional technologies may support statistics, measurement, embedded media, and advertising.

Services in use or detected on the website may include Google Analytics, Google Tag Manager, Google Ads, Google Site Kit, Microsoft Advertising Universal Event Tracking, YouTube or other embedded media, WordPress, Elementor, The7, Wordfence, and hosting or performance services. These providers may process data under their own terms and privacy notices.

Your choices: Use the Cookie and Privacy Preferences page or the Privacy Choices control on the website to accept, reject, or change optional categories. Essential security and consent technologies remain active because they are needed to operate the website and remember your choices. Browser controls, privacy signals, and blocking tools may also affect how optional technologies operate.

4. When information may be disclosed

We do not sell personal information for money. We may disclose limited information to service providers that help operate, secure, measure, or communicate through the website; to professional advisers where necessary; in connection with a business transaction subject to appropriate safeguards; or when required to comply with law, protect rights and safety, or investigate misuse.

Some privacy laws use “sell,” “share,” or “targeted advertising” broadly. Optional advertising and measurement technologies may be treated as sharing for cross-context behavioral advertising. You may opt out through Privacy Choices and any other control presented on the website.

5. California privacy notice

California residents may have rights, subject to applicable exceptions and verification requirements, to know or access categories and specific pieces of personal information, request deletion, request correction, receive information about collection and disclosure practices, and opt out of sale or sharing. You may also have the right to limit certain uses of sensitive personal information and to receive equal service and pricing after exercising privacy rights.

OC Security Audit does not intentionally use sensitive personal information from this public website to infer characteristics. We do not knowingly sell personal information for money. To exercise an applicable right, use our secure contact page and clearly label the request “Privacy Request.” We may need to verify the request and your authority before responding. An authorized agent may submit a request where permitted by law, subject to verification.

6. Data retention

We retain information only for as long as reasonably necessary for the purpose collected, including responding to inquiries, maintaining business and security records, meeting legal or contractual obligations, resolving disputes, and enforcing agreements. Retention periods vary by record type, service-provider configuration, security need, and applicable law. Information that is no longer required is deleted, anonymized, or securely disposed of where practical.

7. Data security

We use administrative, technical, and organizational safeguards designed to protect information appropriate to its nature and the risks involved. No website, transmission method, or storage system can be guaranteed completely secure. If you believe information submitted through this website may have been exposed or misused, please contact us promptly without including additional sensitive data in the initial message.

8. External links and embedded services

The website may link to third-party resources or display embedded content. A third party may collect information when you choose to interact with its content. This policy does not control third-party websites, platforms, products, or privacy practices. Review the applicable provider’s notice before submitting information.

9. Children’s privacy

This website is intended for business professionals and is not directed to children under 13. We do not knowingly collect personal information from children through the public website. If you believe a child has provided personal information, contact us so we can review and delete it where required.

10. International visitors

The website is operated for a United States business audience. If you visit from another jurisdiction, information may be processed in the United States or other locations used by our service providers. Where applicable, you may have additional privacy rights under local law.

11. Changes to this notice

We may update this policy to reflect changes in technology, services, legal requirements, or business practices. The effective date above identifies the current version. Material changes may be highlighted through the website or consent interface when appropriate.

Contact and privacy requests

To ask a privacy question or submit a request, use the OC Security Audit contact page. Please identify the request as a privacy matter and do not include passwords, client evidence, protected health information, or other sensitive data.

Learn about Ali Hassani, CISO, the cybersecurity and IT professional behind OC Security Audit.

OC-Security-Audit-Cybersecurity-Audit-Vulnerability-Assessment-vCISO-services-Irvine-Orange-County-California
Linkedin
© 2026 OC Security Audit. All rights reserved.
Contact info:
949-777-5567
support@OCsecurityAudit.com
Irvine California
  • Cybersecurity Intelligence Center
Go to Top
Cookie Notice

This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.

Essential Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Analytics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Advertising
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}