Security

Security as a habit, not a badge.

This page describes how we aim to work. It does not claim certifications or audits.

Approach

Practices

  1. 01

    Secure development lifecycle

    Threat thinking during design, code review and automated checks.

  2. 02

    Data protection

    Collect the minimum, protect it in transit and at rest, delete when no longer needed.

  3. 03

    Input validation

    Validate on the server as well as the client; never trust input.

  4. 04

    Access control

    Least privilege and explicit authorization on every sensitive action.

  5. 05

    Dependencies

    Few dependencies, pinned versions, regular audits.

  6. 06

    Configuration and transport

    HTTPS only, secure headers, no secrets in front-end code.

  7. 07

    Monitoring and response

    Useful logging without personal data, and a defined incident process.

  8. 08

    Backup and recovery

    Recovery procedures are tested, not assumed.

This website: static files, no cookies, no analytics, no third-party requests, and a restrictive Content Security Policy (scripts and styles from the same origin only) served with HSTS, nosniff, referrer, permissions and framing headers.

Report a concern or ask a question

Tell us what you are building. We will reply with an honest view of scope, risk and approach.

Start a conversation