Services

Security & compliance

Security is the easiest thing in this industry to sell and the hardest for a customer to verify, so ask anyone offering it what they are certified in. Ours is a CISSO, held by the owner who writes the code, and it shapes how every site here gets built, from the first line through the day-to-day care afterward.

Standard on every build

Security that ships by default.

None of the following is an add-on or an upsell. It is how the site arrives, including this one, which sets exactly the headers described below.

Hardened headers by default

Content type sniffing off, framing denied, referrer policy tightened, and camera, microphone and geolocation switched off at the browser. Set on every response, on every build.

HTTPS everywhere

Certificates issued, renewed, and monitored. No mixed content, no expiry surprises on a holiday weekend.

Least data by default

We collect what a form needs to reach you and nothing more. Fewer fields is less to leak.

No third-party tracking

This site runs no analytics and sets no tracking cookies, which is why our privacy policy is short enough to actually read. We will build yours the same way if you want it.

Domain & email

The half of your identity that isn’t the website.

Your domain and your email are the same asset as your site, and they are where small businesses get hurt most often. Both come with every build, and both are watched on a maintenance plan.

Email at your own domain

you@yourbusiness.com rather than a free address. It is the cheapest credibility a small business can buy, and it is a short job to set up properly.

Mail that lands in the inbox

There is a set of records behind every domain that tell the world your email is genuinely from you. Get them wrong and your quotes and invoices go to spam. Leave them off and anyone can send email wearing your name.

Checked, then watched

We confirm that mail from your domain actually arrives, and keep an eye on it afterwards. Most businesses find out this is broken when a customer mentions they never got the estimate.

The domain in your name

Registered to you, renewals watched, locked against transfer. We have rescued enough domains held hostage by a previous web guy to make a point of this one.

Regulated work

When the rules are somebody else's.

Some clients answer to a regulator. We build with those requirements in mind and keep your site aligned as standards move.

HIPAA-conscious builds

For practices handling patient information, we design intake and storage with the requirements in mind and tell you plainly where a website stops and a compliance program starts.

SOX-conscious controls

Change tracking, access discipline, and documented deploys, so an auditor asking who changed what has an answer.

Where we stop

What we will never claim.

We are a web studio with a security-minded owner. We are not your auditor, we do not issue certifications, and we will not tell you that a well-built website makes an organization HIPAA compliant, because it does not. Compliance is a program covering your people and processes, and the site is one part of it. Anyone selling you “compliance” as a website feature is selling you something that does not exist.

Good questions

The things people usually ask.

And if yours isn’t here, just ask, a real person will answer.

Ask what they are certified in, and ask who verified it. Security is the easiest claim to make in this industry and the hardest one for a customer to check, so a specific answer is worth more than a paragraph of reassurance. Ours: the owner holds a CISSO, a Certified Information Systems Security Officer credential, and it is the same person who writes your code and sets up your hosting, not a specialist brought in for the sales call.