Intelligence Into Action
From understanding to action

Proportionate protection

Security and Privacy by Design

Atkinson avoids blanket assurances. We describe the controls, information boundaries, technology environment and responsible parties that apply to a specific engagement.

Atkinson Film-Arts visual for this page.

In brief

Security and Privacy by Design

Who this is for

Buyers, governance, privacy, security, accessibility and procurement teams.

What this page helps you do

Review the public commitments, controls, limits and evidence expected before an engagement advances.

Public posture

Minimize, separate, protect and document

The public website collects only the information required to respond to an inquiry. The deployment package stores form submissions outside the public web root, uses server-side validation, CSRF protection, a honeypot, origin checks and rate limiting. Authenticated SMTP notification is supported through private server configuration outside the public web root. Every valid inquiry is stored before notification is attempted; delivery success or failure is recorded privately and failed notifications are queued for review.

01

Shared responsibility

Security depends on hosting, DNS, TLS, server configuration, updates, mail delivery, access control, backups and operational practice. The website package provides a strong baseline, but final deployment must be reviewed in the actual environment.

Engagement approach

Security is scoped to the workload

01

Information classification

Identify public, internal, confidential, restricted, research-sensitive and regulated material before selecting tools.

02

Environment and access

Define residency, jurisdiction, identity, administrative access, permissions, keys, logs and operating ownership.

03

Application controls

Use least privilege, validation, review, logging, change control, monitoring and tested recovery appropriate to the system.

04

Honest assurance

State exact controls and scope. Do not replace evidence with “secure,” “sovereign,” “compliant” or “protected” as unsupported absolutes.

Reporting a website security concern

Use the contact page and select “Security or privacy concern.” Do not include exploit details, credentials, personal information or confidential client data in a public form. A deployment-specific security contact address may be added to the security.txt file when approved.

Discuss the controls appropriate to your use case

Request a Briefing