Security
Last updated: April 2026
This page describes how IKOAS approaches the security of this website and the information submitted through it. We aim to be factual: we will not claim certifications we do not hold or controls we have not implemented.
Our approach
Security is treated as a baseline requirement, not a marketing claim. We apply reasonable, proportionate controls for a professional services website of this scale. We do not hold SOC 2, ISO 27001, or any formal security certification, and we do not claim to.
Website security
- HTTPS everywhere. All traffic is served over TLS. HTTP requests are redirected to HTTPS. Certificates are managed by our hosting provider.
- Security headers. This site sets HTTP security headers including Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, X-Frame-Options, and Referrer-Policy.
- Input handling. Form inputs are validated server-side. Contact form submissions include a honeypot field to reduce automated spam.
- Rate limiting. API endpoints are rate-limited to reduce abuse.
- Dependencies. We monitor third-party dependencies for known vulnerabilities and update them on a regular basis.
Data minimisation
We collect only what is necessary. The contact form collects the information you provide. The newsletter collects your email address. Server logs record standard technical data. We do not build profiles, run advertising trackers, or share data with marketing platforms.
See our Privacy Policy for full details of what is collected and why.
Hosting infrastructure
This website is hosted on GoDaddy / Airo infrastructure. Physical and network-level security controls are managed by GoDaddy. We rely on their infrastructure security rather than operating our own data centre.
Email security
Outbound email from ikoas.io is sent through our hosting provider's mail infrastructure. We have configured SPF and DKIM records where supported. We do not send unsolicited commercial email.
Third-party providers
We use a small number of third-party services to operate this site. Each is chosen with data minimisation in mind. We do not use advertising networks, social media pixels, or marketing automation platforms on this website. Current providers:
- GoDaddy / Airo — hosting, infrastructure, contact form routing
Responsible disclosure
Found a security issue?
If you believe you have found a security vulnerability on this website, please contact us at [email protected] with a description of the issue. We ask that you do not publicly disclose the issue before we have had a reasonable opportunity to investigate and address it. We will acknowledge receipt and respond as promptly as we can.
We do not currently operate a formal bug bounty programme. We appreciate responsible disclosure and will acknowledge genuine reports.
What we do not claim
To be clear about what this page does not represent:
- We do not hold SOC 2 Type I or Type II certification
- We do not hold ISO 27001 certification
- We do not have a formal penetration-testing schedule
- We do not have a formal incident response programme
- We do not have mandatory 2FA on all internal systems
We apply proportionate controls for a professional services website. If your engagement with IKOAS requires specific security assurances, please raise them during the project scoping process.
Contact
Security questions or disclosures: [email protected]