Skip to content
Comtau
Book a callBook a call

Trust

Security

The most reliable way to secure a website is to give it very little to attack. This one is built that way.

Last updated
Applies to
comtau.com

How the site is built

Static pages
Pre-built HTML. No application server or database behind it.
No accounts
No logins, passwords or user profiles to protect.
No third-party code
No analytics, ad or tag-manager scripts. Fonts are self-hosted.
HTTPS
Pages are delivered over an encrypted connection.

A small attack surface

Every page is generated ahead of time and published as static files. When you visit, no code runs on a server to build the page and no database is queried. The small amount of JavaScript in the browser only handles interface behaviour, such as opening the menu.

Because the site loads nothing from other companies’ servers, a compromised third-party script cannot affect it, and your visit isn’t shared with outside services.

Data minimisation

The only personal information the website handles is what you choose to send through the contact form: your name, work email, optionally your company, and your message. We ask for nothing more. See the Privacy Policy for how it is used.

Reporting a security issue

If you believe you have found a security vulnerability in this website, please tell us through the contact page, with enough detail for us to understand and reproduce it.

While investigating, please:

  • don’t access, change or delete data that isn’t yours
  • don’t disrupt the website or degrade it for other visitors
  • give us reasonable time to address the issue before sharing it publicly

What this page covers

This page describes the comtau.com website only. Security arrangements for client work are agreed within each engagement.