Infrastructure and standards

Ten standards for every company in the group

The holding decides what every company in the group must meet. Each standard below is a requirement of the holding. They apply today to CivSec S.M.A.R.T B.V. and later to every company that follows, which meets them itself and builds to them. Each standard states how you can verify it.

  1. 1. Ownership lies with the client.

    Intellectual property passes once the work is paid for, recorded in a written deed. Client data always belongs to the client and can always be exported.

    How to verify In the company's terms of service.

  2. 2. Leaving is always possible.

    On written request, DNS, hosting, code and analytics are handed over free of charge within five business days, also if there is a dispute.

    How to verify In the terms of service, under guarantees.

  3. 3. Servers and email in the European Union.

    Server functions run in a European region and business email is hosted in a European data centre.

    How to verify In the list of processors in the privacy policy.

  4. 4. Email that cannot be forged.

    Every domain in the group publishes SPF, DKIM and DMARC, with the strictest DMARC policy: messages that fail the check are rejected.

    How to verify In the public DNS records of the domain.

  5. 5. Security headers on every website.

    A strict content security policy, HTTPS the browser can never skip, no embedding in other sites, and limited access to camera, microphone and location.

    How to verify In the response headers of every page.

  6. 6. Tested against the OWASP Top 10.

    Input is validated on the server, forms have a bot check that closes rather than opens when it fails, and secrets never appear in code. Every website publishes an address for reporting security issues.

    How to verify Via /.well-known/security.txt.

  7. 7. Accessible to WCAG 2.2 AA.

    Every project is tested against WCAG 2.2 level AA, and every website has an accessibility statement that says what was and was not measured.

    How to verify In the accessibility statement.

  8. Analytics cookies are only set after the visitor has given consent, on the group's own websites and on those of clients. On the group's own websites, declining is as easy as accepting.

    How to verify In the cookie policy of each website.

  9. 9. Separated data.

    Every product and every client has its own hosting environment and its own data storage. Data is never shared between projects.

    How to verify On request, in an audit.

  10. 10. Nothing goes live without a check.

    A change only goes live after a fixed gate: type checking, build, dead-link check, a scan for leaked keys and an accessibility test. After release a negative test follows: a form without a bot check must be refused.

    How to verify On request, in the delivery file.

This page deliberately names no suppliers. Which parties process data is listed in each company's privacy policy.