The public website is delivered through Cloudflare, uses Sanity as its content-management platform, does not provide public customer accounts and does not store client operational systems or project datasets. Separate third-party services may provide analytics, consent management, forms and email delivery.
security
Security Overview
An overview of DumDum Digital's proportionate approach to protecting systems and information.
- Effective
- 4 August 2026
- Reviewed
- 4 August 2026
Website architecture
Identity and access
Administrative access is limited to authorised users. Controls include individual accounts, multi-factor authentication, least-privilege access, separate administrative access where appropriate, secure credential management and removal of access when no longer required.
Devices and software
Devices used to access business information use supported software, security updates, access protection, encryption where supported and appropriate malware and browser protections. Unnecessary software and browser extensions are avoided.
Data protection
We minimise the personal and confidential information held in our systems. Information is stored using reputable cloud providers and protected through access controls, encryption, supplier safeguards and operational procedures. Client data is kept separate from public website content.
Development and change management
Practices may include version control, review, dependency and vulnerability scanning, testing before deployment, secret management, restricted production access and records of significant changes. Exact controls depend on the size, sensitivity and risk of the engagement.
Suppliers
Supplier selection considers security features, access controls, data handling, resilience, contractual terms, processing location and the consequences of failure. Using a reputable supplier does not transfer away our responsibility to configure and use it appropriately.
Backup and resilience
We use backup, versioning or recovery capabilities appropriate to the information and services involved. Recovery arrangements are selected according to system importance, export availability and the consequences of data loss.
Incident response
Suspected incidents are assessed according to their nature and effect. Response may include containing access, preserving evidence, resetting credentials, engaging suppliers, identifying causes, restoring services, notifying affected parties or regulators where required and applying lessons learned.
Scope of this overview
This overview describes DumDum Digital's general approach. It is not a certification, audit report or guarantee that an incident can never occur. Client-system security depends on the agreed scope and remains a shared responsibility between DumDum Digital, the client and relevant providers.