Data minimisation
Only data required for a clearly stated purpose is collected. Public forms do not use external CAPTCHAs or advertising services.
Security & privacy
Digital solutions are planned around their actual risks. Data minimisation, clear permissions, secure defaults and orderly operations are therefore part of the project from the outset.
Principles
Only data required for a clearly stated purpose is collected. Public forms do not use external CAPTCHAs or advertising services.
Internal areas are separate from the public website. Sessions, login attempts and operations that write data are protected by several technical controls.
Inputs are restricted and validated. Records are stored outside the public web area; file type, signature and integrity are checked.
Backups, recovery, updates, logging, retention and structured handover are defined according to protection needs.
Absolute security does not exist. Measures are selected according to risk, documented, tested and adapted as requirements change. Certifications are mentioned only when they actually exist.
In client projects
The specific scope depends on data types, people affected, availability, integrations and the potential impact of an outage or misuse.
Responsible disclosure
Please report a possible vulnerability confidentially through the designated security channel. Do not include passwords, access codes, real personal data or active malicious code. Reports receive prioritised review and traceable handling.
Security reportGuidance
Security work is guided by GDPR principles, particularly data protection by design and security of processing, as well as recognised web security practices. Required measures are determined for each project based on actual risk.
If a client is subject to NISG 2026 or comparable sector-specific requirements, the supply-chain, evidence, incident and exit requirements passed to Montfort Systems as a direct supplier are specifically defined in the project agreement, catalogue of technical and organisational measures, and SLA. This is not a blanket claim of conformity or certification; project-specific assessment remains decisive.
Article 25 GDPR · Article 32 GDPR · NISG 2026 · OWASP ASVS · privacy notice