Browser isolation
A restrictive content policy, anti-framing rules, type-sniffing prevention and limited browser permissions reduce common injection and clickjacking risks.
Book a consultation ↗Home ↗Security centre
Security is designed into the website journey—from a minimal-data enquiry to a carefully limited browser environment.
Review the controls ↓No website can guarantee that a breach will never occur. SPP uses layered controls to reduce risk, limits the information it handles and reviews the configuration before public launch.
01 / Defence in depth
Practical protection
The architecture is intentionally narrow: collect less, trust less, validate inputs and minimise exposure.
A restrictive content policy, anti-framing rules, type-sniffing prevention and limited browser permissions reduce common injection and clickjacking risks.
Production traffic is served over HTTPS so information is encrypted while travelling between the visitor and the website.
The public site has no advertising trackers. Enquiries request only the information needed to assess a project.
Names, email addresses and project descriptions are validated and limited in length before an enquiry is accepted.
Enquiries accept only same-origin writes, bounded JSON payloads and validated fields. A hidden bot trap and best-effort abuse controls reduce automated submissions.
SPP does not use third-party advertising pixels or behavioural tracking to build a profile of website visitors.
02 / Responsibility boundary
What happens where
You decide what project information to provide and are reminded not to submit access codes, identity documents or banking details.
The website checks required fields, limits payload size and rejects malformed or suspicious submissions.
The authorised studio team reviews the project brief and replies through the official business email channel.
03 / Responsible disclosure
Found something?
Secure by design, transparent by default
The configuration will be reviewed again before the website is opened to the public.