Infrastructure
Security Compliance
Last updated: 19 August 2026
01Scope
This page describes how we handle security for this website and, in general terms, for client engagements. Controls specific to an engagement are agreed in writing for that engagement. We do not currently hold a third-party security certification, and we do not claim one.
02Transport and hosting
The site is served over HTTPS from Google Firebase Hosting. It is a static site: there is no application server and no database behind it, which removes a large share of the usual attack surface.
03Data minimisation
We ask for the least we need to answer you. The site stores no personal data itself; form submissions are delivered straight to our inbox by Web3Forms and bookings are held by Cal.com.
04No payment data
We never collect card or bank details through this site. Any payment for engaged work is handled outside it, through the channel named in the signed agreement.
05Access control
Access to the inbox that receives enquiries, to the hosting project and to the booking account is limited to the managing members and to staff who need it for their work, with multi-factor authentication enabled.
06Client engagements
In delivery work we apply least-privilege access, keep client credentials in a managed secret store rather than in code or chat, and hand over ownership of infrastructure and accounts at the end of an engagement.
07Reporting a vulnerability
If you find a security problem in this site, tell us through the contact form before disclosing it publicly, and give us a reasonable window to fix it. We will confirm receipt and keep you posted. We do not currently run a paid bounty programme.
08Contact
Write to daniel@deltaprotechsol.com, use the form on the home page, or reach us by post at the address above. We answer enquiries about this document at the same address.