Security Statement


Last Updated: July 28, 2026

BrandStory Global handles website enquiries and, in client work, may receive access to business systems, marketing platforms, analytics and project information. Security is managed according to the nature of the work, information and risk.

Safeguards we apply

We apply administrative, technical and organisational measures appropriate to the information and risk. These typically include:

  • Role-based access and least-privilege permissions for website administration, GTM, GA4, Clarity and monday CRM.
  • Multi-factor authentication for administrator and business-system accounts where supported.
  • Encrypted HTTPS transmission and managed hosting.
  • Joiner, mover and leaver access procedures, including prompt account removal.
  • Confidentiality commitments for relevant personnel and contractors.
  • Vendor review before placing personal or client information in a new service.
  • Backups, change control, dependency updates and vulnerability remediation for managed systems.
  • Incident reporting, investigation, containment, recovery and required notification.
  • Periodic access reviews and secure deletion or return at the end of the applicable retention period or engagement.

This statement does not claim ISO 27001, SOC 2, HIPAA, PCI DSS or similar certifications unless separately verified and published.

Reporting a security concern

Send a concise description and affected URL to contact@brandstoryglobal.com. Do not include exploit code, credentials, personal information or confidential client data in the first message. BrandStory does not authorise testing that disrupts services, accesses data, uses social engineering or violates law.