Small surface, by design.
What this site runs, what it collects, and the engagement rules that keep client data out of our hands. Written for your vendor-risk review.
The website
Static site. Every page is pre-built HTML. There are no user accounts, no logins, no sessions, no database, and no server-side application to compromise.
No cookies. The site sets none. Analytics run on Plausible, a cookieless service that collects aggregate page counts only — no personal identifiers, no cross-site tracking.
Forms. The self-diagnostic tools, specimen request and enquiry forms are processed by Netlify Forms over HTTPS. Submissions go to our inbox and to no one else.
Headers. Served with a strict Content-Security-Policy (no inline scripts), HSTS, X-Frame-Options DENY, and nosniff. The one script on the site is fingerprinted with subresource integrity. Built and tested against WCAG 2.2 AA.
Third parties. Netlify (hosting and forms), Plausible (aggregate analytics), and Google (appointment scheduling, on Google’s own page). No advertising or tracking scripts of any kind.
The engagement
No production access. Assessments are designed to stay outside the critical-activity tier of third-party risk guidance: no access to production systems, no customer data, no hosting, and no function your operations depend on. Any request to change that is a material change requiring a written amendment — never an informal favour.
Role titles, not names. Decision owners are recorded as role titles (“Head of Credit Risk”). Individual names are held separately only where operationally essential and deleted at engagement close.
Point-in-time, client-held. Deliverables are observations of conditions at a point in time, prepared for the client alone. See Scope & Limitations for the full terms that travel with every report.
Research data
Self-check responses are used for aggregated benchmarking research under the consent shown at the point of submission: de-identified, no company identified, withdrawal at any time. Details in the Privacy policy.
Ask us anything on this page.
Security questionnaires welcome — most answers are already above.