Server-rendered by default
Most public pages ship without client-side application logic, reducing JavaScript, memory pressure and unnecessary attack surface.
Security at ISIKKO
WIMD Technologies builds and secures ISIKKO. This page states the controls and boundaries represented in the corporate website build without claiming certifications the company has not published.
parent company responsible for building and securing ISIKKO
Website security baseline
The new corporate application removes the vulnerable WordPress dependency and uses a managed, structured publishing path.
Most public pages ship without client-side application logic, reducing JavaScript, memory pressure and unnecessary attack surface.
Marketing content is rendered through approved components. Rich text must be sanitised and is not accepted as arbitrary styling HTML.
Content-type, framing, referrer, permissions and transport policies are configured centrally and tested after deployment.
Sanity tokens, lead webhooks and data-service credentials belong in server-only environment variables, never committed to the public repository.
Directory values are normalised, length-limited and rendered as text. Claimed or verified status is not inferred from a submitted form.
Payment, authentication and vendor-admin systems remain separate codebases and require their own threat modelling, review and monitoring.
Responsible disclosure
Please describe the affected URL, reproduction steps, observed impact and any supporting evidence. Do not access customer data, disrupt services, run denial-of-service tests or publish the issue before the company can investigate.
Report securely by email