Terms & Policies
Security
Website safeguards, handling project information, and how to report a security concern.
Effective
01The scope of this page
This page describes safeguards in IsoData’s current website application and how to raise a concern. The public site introduces our work and accepts project inquiries. It has no customer accounts, payment collection or file-upload feature.
Website safeguards do not establish the security arrangements for a customer project. Those arrangements must be agreed separately before access to restricted data.
02Website safeguards
- Checked submissions. The inquiry endpoint validates fields, limits submission size, rejects malformed requests and rejects a supplied browser origin that does not match the website. A hidden form field helps filter automated spam.
- Controlled delivery. When configured, the server sends inquiries to Formspree over HTTPS. It does not automatically retry uncertain deliveries. Form responses instruct browsers and intermediaries not to cache them.
- Browser protections. The application configures headers to prevent framing, restrict content sources and disable content-type guessing. These reduce specific risks; they do not guarantee that the site is free of vulnerabilities.
- Limited browser storage. The application does not save inquiry drafts in persistent browser storage or include advertising trackers. See our Cookie Policy.
These are application-level measures and do not describe every hosting or provider control. This page does not claim a security certification or independent security audit for IsoData.
04Service providers
Website hosting, inquiry delivery and business email involve service providers. When online form delivery is enabled, Formspree processes the inquiry. Its own safeguards are described on Formspree’s security page.
A provider’s controls or certifications do not certify IsoData’s operations. Our Privacy Policy describes the information these services may receive. No website or email system can guarantee absolute security.
05Report a security concern
See our contact page for inquiry availability. Start your message with “Security report” and include the affected page, when you noticed the issue, its possible impact and the minimum steps needed to understand it. Redact personal information, credentials and confidential material from examples.
If a report needs sensitive evidence, describe it first so an appropriate transfer method can be agreed. Do not access another person’s information, disrupt services or run destructive tests. If you encounter exposed data, stop and report its location without downloading or sharing it.
This reporting channel does not grant permission to test systems or promise a bounty or response deadline. Any testing that requires authorization must be agreed in advance. See your privacy choices for information about privacy requests.