Security and Data Handling

Security and Data Handling

Last updated: 16 June 2026

This page summarises the practical security and data-handling approach used by Cosmic Build Digital Studio. It is intended to explain baseline practices without publishing sensitive operational details.


Security principles

  • Least access: access is limited to the people and systems that reasonably need it.
  • Client ownership: clients should retain control of domains, hosting, and primary accounts.
  • Secure transfer: passwords and sensitive credentials should be shared through approved secure methods rather than ordinary email or forms.
  • Maintained systems: supported software, updates, backups, and monitoring reduce avoidable risk.
  • Proportionate controls: measures are selected according to the sensitivity and scope of the project.

Website build practices

  • Use reputable hosting, themes, plugins, and service providers where possible.
  • Avoid unnecessary plugins and abandoned software.
  • Use encrypted connections for live websites.
  • Apply suitable account permissions and strong authentication.
  • Remove temporary accounts and unused integrations after handover.
  • Keep backups and recovery responsibilities clear.

Client credentials

Clients should not send passwords, payment-card details, private keys, or highly sensitive personal data through a normal website enquiry form.

Project access should be provided through temporary accounts, delegated access, or a secure credential-sharing method where available. The client should rotate credentials and remove unnecessary access after handover.


Project information

Project materials may include business information, content drafts, analytics access, website credentials, and communications. Information is used for the agreed project and shared only with relevant providers or contractors where necessary.

Data retention and privacy rights are explained in the Privacy Policy.


Third-party platforms

Hosting companies, WordPress plugins, analytics tools, payment services, form platforms, email providers, and other integrations have their own security controls and terms. Cosmic Build reviews suitability within the project scope but cannot guarantee the security or uninterrupted availability of an external provider.


Backups and maintenance

Backup, update, monitoring, and incident-response responsibilities are confirmed in the proposal or Care Plan. Without an ongoing support agreement, the client is responsible for maintaining the website after handover.

A backup is useful only when it is current, accessible, and capable of being restored. Hosting-level backups should be supplemented where the risk and project scope justify it.


Security incidents

Suspected incidents should be reported promptly to [security@cosmicbuild.digital] with the affected website, time observed, and a factual description. Do not include passwords or sensitive data in the initial message.

The response will depend on access, the active support agreement, the systems involved, and whether a third-party provider must participate.


Responsible disclosure

Good-faith reports of a potential vulnerability are welcome. Please avoid accessing data that is not yours, disrupting the service, publishing the issue before it can be reviewed, or using automated testing that may affect availability.


No absolute guarantee

No website or online system can be guaranteed completely secure. The purpose of these practices is to reduce avoidable risk, maintain clear ownership, and respond responsibly when an issue is identified.

Contact Cosmic Build

Cosmic Build Digital Studio

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.