Security

Security

Last updated: 29 August 2026. What we've built in to protect this site, what we're still strengthening, and how to reach us if you find something we've missed.

Why we publish this

We're an identity and access management consultancy — holding our own site to the same standard we advise clients to apply is table stakes, not a marketing exercise. This is a plain account of what's actually in place, not a compliance certificate we haven't earned.

What's in place today

  • Encrypted everywhere. Every page and asset on this site is served over HTTPS, with HSTS preloading so a browser never even attempts an insecure connection to this domain.
  • A restrictive content policy. A CSP and standard hardening headers limit what a compromised or injected script could do, even in the worst case — no inline script execution, no framing by other sites, and less exposed to other sites via the referrer than the browser default.
  • Independently graded encryption. This site's TLS configuration holds an A+ rating from Qualys SSL Labs, one of the industry-standard tools for testing it.
  • Nothing to steal. There are no user accounts, no database this site's front end can reach, and no personal data stored beyond what you choose to submit through our Contact form. A smaller target is a safer one.
  • No exposed source or secrets. Our source code lives in a private repository, and no credentials, API keys, or internal configuration files are ever served publicly from this domain.
  • Authenticated email. Email sent from our domain is authenticated using SPF and DKIM, making it harder for someone to convincingly forge a message that appears to come from us.
  • A way to reach us. If you find a genuine security issue, our published disclosure contact — security.txt — tells you exactly how.

What we're still strengthening

In the interest of being straight about it rather than glossing over it:

  • We're moving our email-authentication policy — DMARC — toward full enforcement over the coming weeks, having only recently tightened the SPF and DKIM setup it depends on.
  • We haven't commissioned an independent penetration test of this specific site. Given it's a static site with no backend, no authentication, and no database, we don't think one would currently be proportionate — but we revisit that judgement as the site grows.

Found something? Tell us

If you've found a genuine security issue — not general feedback — please use the contact details in our security.txt file, or email contact@iam-tech.co.uk directly. Provided you act in good faith, avoid accessing or changing data beyond what's needed to demonstrate the issue, and give us a reasonable chance to fix it before going public, we'll acknowledge your report and won't pursue legal action over it.

Changes to this page

We'll update this page as our security practices evolve. The date at the top reflects the most recent revision.

Have a question we haven't covered?

Get in touch directly and we'll answer it honestly.

Talk to us