Home/Security

Security

How Duyuz approaches website and project security — practical measures, not theatre.

Company details

Consistent identity across duyuz.com

The same brand, contact and legal fields appear on About, Contact, Imprint and related trust pages.

Scope

This page describes how Duyuz approaches security for duyuz.com and for client projects we deliver. It is not a SOC 2 / ISO certification claim. Formal assurances, if required, are confirmed in writing per engagement.

Transport & hosting

Public sites we ship are served over HTTPS. Hosting and DNS partners are chosen for reliable TLS and routine patching. Exact stack varies by project and is documented in the proposal.

Access & credentials

Client credentials and admin access are shared through agreed channels, rotated when staff change, and never published in marketing materials. We do not store payment card data on duyuz.com forms.

Application hygiene

Forms use CSRF tokens where applicable. Updates and dependency care are part of published website-care retainers when scoped. Security fixes for active care clients are prioritised.

Incident contact

If you believe you have found a security issue on duyuz.com, email hello@duyuz.com with enough detail to reproduce. Do not include sensitive personal data in the first message unless requested.

Limits

Security controls are scoped per project. For regulated industries, specific requirements are confirmed in writing.