Security & privacy

Security is part of the architecture, not an add-on.

Digital solutions are planned around their actual risks. Data minimisation, clear permissions, secure defaults and orderly operations are therefore part of the project from the outset.

  • Data protection by design
  • Documented safeguards
  • Responsibility beyond handover

Principles

Safeguards follow data, roles and risks.

01

Data minimisation

Only data required for a clearly stated purpose is collected. Public forms do not use external CAPTCHAs or advertising services.

02

Access protection

Internal areas are separate from the public website. Sessions, login attempts and operations that write data are protected by several technical controls.

03

Secure processing

Inputs are restricted and validated. Records are stored outside the public web area; file type, signature and integrity are checked.

04

Orderly operations

Backups, recovery, updates, logging, retention and structured handover are defined according to protection needs.

No blanket security promises

Absolute security does not exist. Measures are selected according to risk, documented, tested and adapted as requirements change. Certifications are mentioned only when they actually exist.

In client projects

Security is treated as a testable requirement.

The specific scope depends on data types, people affected, availability, integrations and the potential impact of an outage or misuse.

Before implementation

  • Clarify data flows and responsibilities
  • Assess protection needs and misuse scenarios
  • Define roles, permissions and deletion periods

During implementation

  • Secure defaults and minimum permissions
  • Server-side validation and protected secrets
  • Traceable changes and acceptance

During operation

  • Test updates and recovery
  • Detect, assess and document incidents
  • Consistently revoke access when roles change

Responsible disclosure

Found a security issue?

Please report a possible vulnerability confidentially through the designated security channel. Do not include passwords, access codes, real personal data or active malicious code. Reports receive prioritised review and traceable handling.

Security report

Guidance

Law and recognised practice.

Security work is guided by GDPR principles, particularly data protection by design and security of processing, as well as recognised web security practices. Required measures are determined for each project based on actual risk.

If a client is subject to NISG 2026 or comparable sector-specific requirements, the supply-chain, evidence, incident and exit requirements passed to Montfort Systems as a direct supplier are specifically defined in the project agreement, catalogue of technical and organisational measures, and SLA. This is not a blanket claim of conformity or certification; project-specific assessment remains decisive.

Article 25 GDPR · Article 32 GDPR · NISG 2026 · OWASP ASVS · privacy notice