Infrastructure

Security Compliance

Last updated: 19 August 2026

01Scope

This page describes how we handle security for this website and, in general terms, for client engagements. Controls specific to an engagement are agreed in writing for that engagement. We do not currently hold a third-party security certification, and we do not claim one.

02Transport and hosting

The site is served over HTTPS from Google Firebase Hosting. It is a static site: there is no application server and no database behind it, which removes a large share of the usual attack surface.

03Data minimisation

We ask for the least we need to answer you. The site stores no personal data itself; form submissions are delivered straight to our inbox by Web3Forms and bookings are held by Cal.com.

04No payment data

We never collect card or bank details through this site. Any payment for engaged work is handled outside it, through the channel named in the signed agreement.

05Access control

Access to the inbox that receives enquiries, to the hosting project and to the booking account is limited to the managing members and to staff who need it for their work, with multi-factor authentication enabled.

06Client engagements

In delivery work we apply least-privilege access, keep client credentials in a managed secret store rather than in code or chat, and hand over ownership of infrastructure and accounts at the end of an engagement.

07Reporting a vulnerability

If you find a security problem in this site, tell us through the contact form before disclosing it publicly, and give us a reasonable window to fix it. We will confirm receipt and keep you posted. We do not currently run a paid bounty programme.

08Contact

Write to daniel@deltaprotechsol.com, use the form on the home page, or reach us by post at the address above. We answer enquiries about this document at the same address.