Security

Security

How client data and systems are handled during consulting engagements, what this website itself stores, and how to report a vulnerability. Written for the security team that will read it before the engagement starts.

Client data in engagements

Engagement work happens in client-owned environments wherever possible: your Azure subscriptions, your repositories, your tooling. Client data stays in client systems - it is not copied to Weldon Web machines or storage unless a specific deliverable requires it and it is agreed in writing first.

Where AI tooling is used during delivery, it is used within whatever policy the client sets. If you have constraints on AI usage against your code or data, they are respected - designing those constraints is literally one of the services offered.

Access and credentials

  • · Least privilege by default: access scoped to the systems the engagement actually needs, granted through your identity provider, ideally as a guest in your tenant.
  • · No shared accounts, no credentials over email or chat. Client secrets live in the client's secret store, not in code or notes.
  • · Access should be revoked at the end of the engagement - offboarding is part of the closing checklist, and a reminder to do it is included in the handover.

This website

This site runs on Vercel (hosting), Postgres (content database), Azure Blob Storage (media) and Resend (email delivery). It stores no client engagement data.

The only personal data it collects is what you submit through the contact form (name, email, message, and the submitting IP address for rate limiting), which is delivered by email and retained as described in the privacy policy.

Vulnerability disclosure

Report vulnerabilities in this site or anything else Weldon Web operates to security@weldonweb.co.uk. I aim to acknowledge reports within two business days and to confirm remediation timing within five.

No PGP key today. If that is a blocker for your disclosure policy, tell me and I will publish one.

Honest about scale

Weldon Web is a small operation: one engineer, with associates brought in when scope requires. There is no SOC 2 today; do not let me invent one. What you get instead is a small, auditable footprint and direct answers from the engineer who does the work. Professional indemnity (£1m), public and products liability (£1m) and employers' liability (£10m) insurance are in place, with certificates on request.

If your procurement or security team needs something not covered here (a specific attestation, custom DPA terms, a copy of an insurance certificate), ask via the contact form.