Information classification
Identify public, internal, confidential, restricted, research-sensitive and regulated material before selecting tools.
Atkinson avoids blanket assurances. We describe the controls, information boundaries, technology environment and responsible parties that apply to a specific engagement.

The public website collects only the information required to respond to an inquiry. The deployment package stores form submissions outside the public web root, uses server-side validation, CSRF protection, a honeypot, origin checks and rate limiting. Mail notification is optional and configured through server environment variables rather than embedded credentials.
Security depends on hosting, DNS, TLS, server configuration, updates, mail delivery, access control, backups and operational practice. The website package provides a strong baseline, but final deployment must be reviewed in the actual environment.
Identify public, internal, confidential, restricted, research-sensitive and regulated material before selecting tools.
Define residency, jurisdiction, identity, administrative access, permissions, keys, logs and operating ownership.
Use least privilege, validation, review, logging, change control, monitoring and tested recovery appropriate to the system.
State exact controls and scope. Do not replace evidence with “secure,” “sovereign,” “compliant” or “protected” as unsupported absolutes.
Use the contact page and select “Security or privacy concern.” Do not include exploit details, credentials, personal information or confidential client data in a public form. A deployment-specific security contact address may be added to the security.txt file when approved.
Large, deliberate imagery helps visitors understand the people, places, systems and creative outcomes behind the offer without turning the site into a catalogue.



