L/06Legal
Security
This page describes how we approach the security of this website and of the information people share with us. It also states what we do not claim.
- Document
- Security
- Last updated
- 22 September 2026
- Applies to
- www.onioninfosec.com
On this page
1. How this website is built
The website is designed to have a small attack surface and to hold as little data as possible.
- Static site. Pages are pre-built files served from Microsoft Azure Static Web Apps. There is no database and no content management system behind the website.
- No third-party scripts. The website loads no analytics, advertising, font, CAPTCHA or widget code from other domains.
- Security headers. The website sends security response headers, including a content security policy that restricts where scripts, styles and other resources can load from.
- Encryption in transit. All traffic to the website uses HTTPS.
- Least-privilege access. Access to hosting, deployment and DNS is limited to the people who need it.
2. How contact form data is handled
The contact form posts to a serverless function on this domain. The function validates the submission, applies a hidden-field check and a timing check to filter automated submissions, and delivers the enquiry to our team by email. The website itself does not store submissions.
Form submissions are delivered through Google Workspace, our business email system. Please do not send passwords, vulnerability details of your own systems or other confidential information through the contact form. See the Privacy Policy for how enquiry data is used and retained.
3. Information shared during engagements
Information that clients share with us during an engagement is governed by non-disclosure agreements and by the engagement agreement. It is handled under least-privilege access, which means only the people working on the engagement can reach it.
Specific security requirements, such as data location, retention and return or deletion at the end of the work, are agreed in the contract. See Data Protection.
4. What we do not claim
We prefer to state plainly what is and is not in place.
- Onion Infosec does not claim any company-level security certification, attestation or accreditation.
- Professional certifications mentioned on this website are held by members of our team as individuals. They are not company accreditations.
- No system is completely secure, and we do not claim that this website or our systems are free of vulnerabilities.
5. Reporting a vulnerability
If you believe you have found a security issue in this website, please report it under our Vulnerability Disclosure Policy. The policy explains the scope, what to include in a report and how we treat good-faith research.
6. Security contact
Security contact: security@onioninfosec.com. If your report includes sensitive details, describe the issue in general terms first and we will arrange a suitable channel for the rest.
A machine-readable copy of our security contact details is published at /.well-known/security.txt on this domain.
