Safeguards we apply
We apply administrative, technical and organisational measures appropriate to the information and risk. These typically include:
- Role-based access and least-privilege permissions for website administration, GTM, GA4, Clarity and monday CRM.
- Multi-factor authentication for administrator and business-system accounts where supported.
- Encrypted HTTPS transmission and managed hosting.
- Joiner, mover and leaver access procedures, including prompt account removal.
- Confidentiality commitments for relevant personnel and contractors.
- Vendor review before placing personal or client information in a new service.
- Backups, change control, dependency updates and vulnerability remediation for managed systems.
- Incident reporting, investigation, containment, recovery and required notification.
- Periodic access reviews and secure deletion or return at the end of the applicable retention period or engagement.
This statement does not claim ISO 27001, SOC 2, HIPAA, PCI DSS or similar certifications unless separately verified and published.
Reporting a security concern
Send a concise description and affected URL to contact@brandstoryglobal.com. Do not include exploit code, credentials, personal information or confidential client data in the first message. BrandStory does not authorise testing that disrupts services, accesses data, uses social engineering or violates law.