Who this is for
Buyers, governance, privacy, security, accessibility and procurement teams.
Proportionate protection
Atkinson avoids blanket assurances. We describe the controls, information boundaries, technology environment and responsible parties that apply to a specific engagement.

In brief
Buyers, governance, privacy, security, accessibility and procurement teams.
Review the public commitments, controls, limits and evidence expected before an engagement advances.
The public website collects only the information required to respond to an inquiry. The deployment package stores form submissions outside the public web root, uses server-side validation, CSRF protection, a honeypot, origin checks and rate limiting. Authenticated SMTP notification is supported through private server configuration outside the public web root. Every valid inquiry is stored before notification is attempted; delivery success or failure is recorded privately and failed notifications are queued for review.
Security depends on hosting, DNS, TLS, server configuration, updates, mail delivery, access control, backups and operational practice. The website package provides a strong baseline, but final deployment must be reviewed in the actual environment.
Identify public, internal, confidential, restricted, research-sensitive and regulated material before selecting tools.
Define residency, jurisdiction, identity, administrative access, permissions, keys, logs and operating ownership.
Use least privilege, validation, review, logging, change control, monitoring and tested recovery appropriate to the system.
State exact controls and scope. Do not replace evidence with “secure,” “sovereign,” “compliant” or “protected” as unsupported absolutes.
Use the contact page and select “Security or privacy concern.” Do not include exploit details, credentials, personal information or confidential client data in a public form. A deployment-specific security contact address may be added to the security.txt file when approved.