IKMA
Legal

Security

Last updated: August 15, 2026

Security is part of how we build — for this site and for the projects we ship for clients. Here's what that means in practice.

1. This website

  • Served exclusively over HTTPS.
  • Security headers — including a Content Security Policy, X-Frame-Options, X-Content-Type-Options, and a restrictive Permissions-Policy — are set on every response.
  • The contact form validates and size-limits its inputs and is rate-limited to prevent abuse.
  • Dependencies are kept current and monitored for known vulnerabilities.

2. Client data and confidentiality

Project details shared with us are treated as confidential — we're comfortable signing an NDA before detailed discussions begin, and our standard engagement terms carry a confidentiality commitment that survives after a project ends. Where a project involves processing personal data on a client's behalf, we put a GDPR-compliant data processing agreement in place before that processing starts.

3. Infrastructure

This site is hosted on Vercel's platform, and outbound email is delivered through Resend. Both are established providers with their own security and compliance programs; neither receives more data than is needed to do their job.

4. Reporting a vulnerability

If you believe you've found a security issue in this site, we'd genuinely like to know. Email info@ikma.se with what you found and how to reproduce it, and give us a reasonable window to investigate and fix it before disclosing it publicly. Please avoid actions that could degrade the site or access data that isn't yours.

5. Contact

Security questions, general or project-specific: info@ikma.se.