Security
How this site and client material are protected, what we do not claim, and what happens if something goes wrong.
Last updated August 2026
This states the specific things we do to keep this site and client material secure — from a content security policy with no external script origin, to multi-factor authentication and encrypted client data. It also says what we do not hold: no ISO 27001 or SOC 2 certification. It covers this website and how we handle client material generally. It does not cover how to report a vulnerability, which Responsible Disclosure covers, or a specific engagement's own added security requirements.
What we do to keep this site and the material on it safe. It is deliberately specific: a security page that says only that we take security seriously tells you nothing.
This website
- Served over HTTPS.
- A Content Security Policy that permits no external script origin at all.
- No third-party scripts — no analytics, no advertising, no tag manager.
- Fonts and JavaScript libraries served from this domain, so no visitor’s IP address is handed to a third party on page load.
- Uploaded SVG files sanitised against an allowlist before they are written to disk, because an SVG is XML and a same-origin one is not stopped by any CSP.
- Gated files stored outside the web root and served through a checked, expiring link rather than an unguessable URL.
- Administrative access throttled against brute force; user enumeration and XML-RPC disabled.
Client material
Held in systems we control, encrypted in transit and at rest, accessible only to the people working on that engagement. Not kept longer than the engagement and any agreed retention period require.
Our own working practices
- Multi-factor authentication on every account that supports it.
- Full-disk encryption on every machine used for client work.
- A password manager rather than reused credentials.
- Access reviewed when an engagement ends, not when someone remembers.
What we do not claim
We are not certified to ISO 27001 or SOC 2. We are a small firm and we would rather say that than imply an audit we have not had.
If your procurement process requires a certification, tell us early and we will say honestly whether we can meet it. We will not start a process we cannot finish in order to keep a conversation alive.
Dependencies
This site runs on WordPress with a custom theme and our own plugins. Third-party code is kept to a minimum — the motion library is the only one, and it is vendored into the theme rather than loaded from a CDN. Security updates are applied promptly, and we track what versions are running rather than assuming.
If something goes wrong
We will tell affected clients directly and quickly: what happened, what was involved, what we are doing about it, and what if anything you need to do. We will not wait for a complete picture before telling you there is a problem, and we will not describe an incident as a “security event” when it was a breach.
Reporting a problem
If you have found a vulnerability, see our Responsible Disclosure policy. We will not treat a good-faith report as an attack.
Contact us
For security questions, or to request more detail for a procurement process:
- XONIK
- 3/3B, Saket Nagar
- Bhopal, Madhya Pradesh 462024
- India
- Email: security@xonik.com
We are not certified to ISO 27001 or SOC 2, and this page does not imply an audit we have not had. It does not cover how to report a vulnerability — see Responsible Disclosure for that. And it does not cover security requirements specific to one engagement; where a client agreement adds to what is here, the agreement controls for that work.
Questions we get asked
Questions about this policy
Are you ISO 27001 or SOC 2 certified?
No. We are a small firm and we would rather say so than imply an audit we have not had.
Do you use third-party analytics?
No. There is no third-party script of any kind on this site, and the content security policy would not permit one.
How is client material protected?
Encrypted in transit and at rest, in systems we control, accessible only to the people working on that engagement.
What happens if there is a breach?
We tell affected clients directly and quickly, with what happened and what we are doing, before we have the complete picture.
Can you complete our security questionnaire?
Usually, yes. Send it over. Where the honest answer is no, we will say no rather than write something evasive.