Security

Security and privacy

This page describes the security practices Sendoris applies to this website and to client work. It is a description of our practices, not a certification.

Last updated

This website

The site is served over HTTPS only. It has no public database of visitor data and no public sign-up.

Administrative areas require authentication and are excluded from search indexing.

Client work

Access to client systems is limited to the consultants working on that engagement, and is removed when the work ends.

We use per-user accounts rather than shared logins, and we prefer read-only access wherever it is enough.

Where we build software, we design access rules so a user can only reach their own data, and we review those rules before launch.

Reporting a vulnerability

If you believe you have found a security issue on this website or in something we built, contact us through the contact page with enough detail to reproduce it. Please do not test in a way that affects other people's data.

We will confirm receipt, investigate, and tell you what we found.

What we do not claim

We do not claim any formal certification, audit outcome or compliance status. Where a client needs one, we say so plainly rather than implying it.