security

Security Overview

An overview of DumDum Digital's proportionate approach to protecting systems and information.

Effective
4 August 2026
Reviewed
4 August 2026

Website architecture

The public website is delivered through Cloudflare, uses Sanity as its content-management platform, does not provide public customer accounts and does not store client operational systems or project datasets. Separate third-party services may provide analytics, consent management, forms and email delivery.

Identity and access

Administrative access is limited to authorised users. Controls include individual accounts, multi-factor authentication, least-privilege access, separate administrative access where appropriate, secure credential management and removal of access when no longer required.

Devices and software

Devices used to access business information use supported software, security updates, access protection, encryption where supported and appropriate malware and browser protections. Unnecessary software and browser extensions are avoided.

Data protection

We minimise the personal and confidential information held in our systems. Information is stored using reputable cloud providers and protected through access controls, encryption, supplier safeguards and operational procedures. Client data is kept separate from public website content.

Development and change management

Practices may include version control, review, dependency and vulnerability scanning, testing before deployment, secret management, restricted production access and records of significant changes. Exact controls depend on the size, sensitivity and risk of the engagement.

Suppliers

Supplier selection considers security features, access controls, data handling, resilience, contractual terms, processing location and the consequences of failure. Using a reputable supplier does not transfer away our responsibility to configure and use it appropriately.

Backup and resilience

We use backup, versioning or recovery capabilities appropriate to the information and services involved. Recovery arrangements are selected according to system importance, export availability and the consequences of data loss.

Incident response

Suspected incidents are assessed according to their nature and effect. Response may include containing access, preserving evidence, resetting credentials, engaging suppliers, identifying causes, restoring services, notifying affected parties or regulators where required and applying lessons learned.

Scope of this overview

This overview describes DumDum Digital's general approach. It is not a certification, audit report or guarantee that an incident can never occur. Client-system security depends on the agreed scope and remains a shared responsibility between DumDum Digital, the client and relevant providers.