Data Security
Understand public inquiry safeguards, client responsibilities, and the boundaries of a project-specific security review.
Public website inquiries
Use the public form only for general project context. Do not submit passwords, credentials, confidential records, regulated data, or sensitive customer information.
Form safeguards
The form implementation validates submitted fields and includes consent, a spam trap, request-origin checks, rate limiting, and single-use challenge verification. Form delivery requires the corresponding runtime services to be configured. These measures do not guarantee that all abuse or failures will be prevented.
Optional analytics
The website requests optional analytics only after the visitor allows analytics. Page tracking uses pathnames instead of query-string prefills. Sensitive form text is excluded from analytics events.
Project-specific responsibilities
Data classification, authorized access, hosting, vendors, retention, backup and recovery responsibilities, acceptance criteria, and support ownership must be agreed for each project. A public marketing page does not establish controls for every application or client environment.
Security-review boundaries
A project review identifies requirements, relevant risks, and verification appropriate to the agreed scope. It does not imply independent penetration testing, an audit, a certification, guaranteed uptime, absolute security, or a legal compliance determination. Specialist assessment must be scoped separately when required.
Client responsibilities
Use the agreed secure channels for project access and sensitive material. Provide access only with authorization, identify the responsible internal owner, and confirm applicable data-handling and specialist requirements before implementation.
Questions and next steps
Contact Stathra about project requirements or review the Privacy Policy for visitor-data practices.