Security
Security as a habit, not a badge.
This page describes how we aim to work. It does not claim certifications or audits.
Approach
Practices
- 01
Secure development lifecycle
Threat thinking during design, code review and automated checks.
- 02
Data protection
Collect the minimum, protect it in transit and at rest, delete when no longer needed.
- 03
Input validation
Validate on the server as well as the client; never trust input.
- 04
Access control
Least privilege and explicit authorization on every sensitive action.
- 05
Dependencies
Few dependencies, pinned versions, regular audits.
- 06
Configuration and transport
HTTPS only, secure headers, no secrets in front-end code.
- 07
Monitoring and response
Useful logging without personal data, and a defined incident process.
- 08
Backup and recovery
Recovery procedures are tested, not assumed.
This website: static files, no cookies, no analytics, no third-party requests, and a restrictive Content Security Policy (scripts and styles from the same origin only) served with HSTS, nosniff, referrer, permissions and framing headers.
Report a concern or ask a question
Tell us what you are building. We will reply with an honest view of scope, risk and approach.
Start a conversation