Security Statement


Last Updated: July 28, 2026

BrandStory Global handles website enquiries and, in client work, may receive access to business systems, marketing platforms, analytics and project information. Security is managed according to the nature of the work, information and risk.

Safeguards to verify before publishing

The following are controls to verify with evidence before converting them into present-tense public claims. Do not claim ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR certification, penetration-testing frequency, encryption at rest, 24/7 monitoring or fixed breach-notification hours unless verified.

  • Role-based access and least-privilege permissions for website administration, GTM, GA4, Clarity and monday CRM.
  • Multi-factor authentication for administrator and business-system accounts where supported.
  • Encrypted HTTPS transmission and reputable managed hosting.
  • Joiner, mover and leaver access procedures, including prompt account removal.
  • Confidentiality commitments for relevant personnel and contractors.
  • Vendor review before placing personal or client information in a new service.
  • Backups, change control, dependency updates and vulnerability remediation for managed systems.
  • Incident reporting, investigation, containment, recovery and required notification.
  • Periodic access reviews and secure deletion or return at the end of the applicable retention period or engagement.

Reporting a security concern

Send a concise description and affected URL to info@brandstory.in. Do not include exploit code, credentials, personal information or confidential client data in the first message. BrandStory does not authorise testing that disrupts services, accesses data, uses social engineering or violates law.