Security at ISIKKO

Trust requires more than a security badge.

WIMD Technologies builds and secures ISIKKO. This page states the controls and boundaries represented in the corporate website build without claiming certifications the company has not published.

WIMD

parent company responsible for building and securing ISIKKO

Website security baseline

Reduce the exposed surface. Validate every boundary.

The new corporate application removes the vulnerable WordPress dependency and uses a managed, structured publishing path.

01

Server-rendered by default

Most public pages ship without client-side application logic, reducing JavaScript, memory pressure and unnecessary attack surface.

02

Structured content rendering

Marketing content is rendered through approved components. Rich text must be sanitised and is not accepted as arbitrary styling HTML.

03

Security response headers

Content-type, framing, referrer, permissions and transport policies are configured centrally and tested after deployment.

04

Secret separation

Sanity tokens, lead webhooks and data-service credentials belong in server-only environment variables, never committed to the public repository.

05

Untrusted directory data

Directory values are normalised, length-limited and rendered as text. Claimed or verified status is not inferred from a submitted form.

06

Independent production review

Payment, authentication and vendor-admin systems remain separate codebases and require their own threat modelling, review and monitoring.

Responsible disclosure

Found a security issue?

Please describe the affected URL, reproduction steps, observed impact and any supporting evidence. Do not access customer data, disrupt services, run denial-of-service tests or publish the issue before the company can investigate.

Report securely by email