Your data is part of the product. We treat it that way.
Security and data integrity are not afterthoughts. They are part of how we approach software from the beginning.
We describe only controls that are implemented and can be demonstrated. We hold no security certifications and make no compliance claims. Controls on a client project depend on that project, and we agree them in writing.
Data integrity
On the work we build, we design for accurate and consistent data:
- Input validation on every form, on the server as well as in the browser.
- Controlled data changes: who may change what, and when.
- Database-backed storage with constraints where the data model calls for them.
Access control
- Authentication and role-based permissions, with least privilege as the default.
- Restaurant POS (in development) is built with Argon2id password hashing and cookie sessions with CSRF protection.
Data protection
- Secrets and API keys are kept out of front-end code.
- Restaurant POS (in development) is designed to run on the restaurant's own hardware on a private network, so daily operation does not depend on the cloud.
We do not claim a specific encryption standard, backup regime or disaster-recovery procedure on this page. We set these out for each client project.
This website
- Served over HTTPS by Cloudflare, with security headers (a content security policy, HSTS, no framing, no content-type sniffing).
- The contact form validates input on the server and uses a spam trap. The mail provider's API key is held server-side, never in the page.
- No cookies, no analytics and no advertising trackers. Fonts are served from this site.
- The site is static. There is no admin area and no database of visitors.
Report a vulnerability
If you believe you have found a security issue on this website or in our software, please report it through the contact form, choosing the topic "Security report". Include what you found, where, and steps to reproduce.
- Please do not access other people's data or disrupt the service.
- Give us reasonable time to fix the issue before sharing it publicly.
- We will acknowledge good-faith reports and reply by email.
A security.txt file is published for researchers.