Security posture

We use practical safeguards for a web development business, avoid unnecessary tracking, limit access to client materials, and do not store full payment card numbers on this website.

01What This Page Covers

This page describes public-facing security practices for the website, project inquiries, client communications, development materials, credentials, technical access, payment-related data, and support work.

02Website Security

  • Production pages should be served over HTTPS.
  • We avoid unnecessary third-party tracking and advertising scripts.
  • Optional non-essential tags are controlled by the consent manager.
  • We keep public website dependencies and hosting configuration under review.
  • We do not ask for full payment card numbers through our own website forms.

03Payment Security

If online card payments are offered, card information should be handled by third-party payment processors rather than stored by this website.

We may receive transaction status, invoice, refund, and dispute details needed to provide customer support and maintain business records.

04Client Project Information

  • Project information is used for scoping, design, development, launch, maintenance, support, billing, and records.
  • Access to client records and project materials is limited to people and providers who need it for business purposes.
  • We use reputable providers for hosting, email, project management, repository access, form handling, invoicing, and related operations.

05Credentials and Technical Access

Web projects may require domain, hosting, CMS, analytics, repository, API, or ecommerce access. We use those details only for the agreed project or support work and remove or revoke access when it is no longer needed whenever practical.

  • Use temporary credentials or role-based access when possible.
  • Do not send passwords through public comments or unsecured shared documents.
  • Tell us when access should be removed, rotated, or limited.
  • Use multi-factor authentication on hosting, domain, CMS, repository, and payment accounts wherever available.

06Incident Response

If we become aware of a security incident involving personal information, we will investigate, take appropriate steps to reduce harm, and notify affected people or regulators when required by law.

For EEA/UK personal data incidents where notification is required, we aim to support applicable 72-hour regulatory assessment and notification timelines.

07Client Security Tips

  • Use unique passwords and multi-factor authentication.
  • Limit each account to the role needed for the project.
  • Rotate credentials after a project ends if long-term support is not active.
  • Avoid sending highly sensitive information unless it is needed for the work and an appropriate handling method is agreed.