Studio Halden

Security

Client work is confidential by default. Here is how we protect the information you trust us with.

Data protection

  • HTTPS everywhere, with HSTS: data is encrypted in transit.
  • Our database is encrypted at rest and backed up nightly with AES-256 encryption.
  • Payments run on Stripe's hosted pages; we never handle card numbers.
  • We keep only what we need and delete it on a fixed schedule (see our privacy policy).

Access control

  • Staff sign-in requires a password and an authenticator app (2FA).
  • Repeated failed sign-ins lock the account, and every sign-in triggers an alert.
  • Access is limited to the people working on your project, and removed when work ends.
  • Every staff action in our console is written to an audit log.

Application security

  • Strict security headers, including a content security policy and clickjacking protection.
  • Integrations (payments, scheduling) only accept cryptographically signed requests.
  • Rate limits and spam protection on every public form.
  • Automated dependency updates, secret scanning, and hourly uptime and certificate checks.

Report a vulnerability

If you believe you've found a security issue, email info@studiohalden.com with the subject “Security report”. Please give us reasonable time to fix it before sharing it publicly, and don't access data that isn't yours. We'll acknowledge reports within three business days.

Return to the studio