Security

A static website with minimal data processing

The content and scans remain fully usable without Analytics. Google Analytics runtime code loads only after consent; scan answers are never sent to Google. A contact or Automation request is sent only after explicit review and confirmation.

In short

The website is static. External Google Analytics runtime code loads only after explicit consent. Security headers restrict allowed scripts, framing, referrers and browser capabilities. One allowlisted Formspree endpoint handles deliberately submitted Automation requests; hosting, domains, monitoring and incidents also require operational control.

Explore

Technical foundation

CSP

Restricted content sources

Styles and site code come from the website build; only the Google Analytics tag may load externally after consent. Framing and plug-ins remain restricted.

DATA

Minimal data flow

Analytics only after consent; no uploads, AI processing or direct CRM connection. The approved Formspree request path remains separate.

LOCAL

Local scans

Answers are processed only in browser memory while the scan is in use.

CHECK

Automated checks

Routes, links, metadata, headers and unwanted network patterns are tested for every release.

Signals

Operational control

  • Business accounts with MFA and recovery responsibility.
  • Domain, DNS, TLS and mailbox control.
  • Named owners for security, privacy, content and incidents.
  • Monitoring of availability, headers and contact routes.
  • A tested recovery and fallback procedure.
Boundary

Security report