Least privilege and access control
User and administrator access is limited according to job requirements. Administration screens are protected through authentication and an email allowlist; authorisation is checked again when private files are downloaded.
Communication and data security
Website traffic is transmitted over HTTPS. Security headers, same-origin checks, form validation, file-type controls and size limits are used to reduce misuse risks.
Private files
Files uploaded through the project form do not receive public links. They are downloaded through a private endpoint only when requested by an authorised administrator, and download responses are excluded from browser caching.
Logging, monitoring and backup
Application errors and critical transaction states may be monitored for troubleshooting. The backup, retention and restoration approach is determined according to the sensitivity of the system’s data and its business-continuity requirements.
Updates and vulnerability management
Components, configurations and application flows are reviewed as part of regular maintenance. Identified vulnerabilities are prioritised according to risk and impact.
Shared responsibility
No technical system can guarantee absolute security. Security is addressed across software, the hosting provider, user accounts, strong passwords, device security and the customer’s access management. Security notices may be sent to iletisim@nsdij.com.
