How we handle your data, honestly and specifically.
We're a small, early-stage studio — this page describes our actual current setup, not a compliance checklist we don't yet meet.
This website, and our project demos, run on Netlify.
All traffic is served over HTTPS with an automatically issued and renewed TLS certificate. Our marketing site is static — there is no database or backend attached to anvilstack.co itself.
Every engagement's infrastructure is scoped to that project.
Client software we build is hosted and secured according to what that specific project needs — this varies by engagement, and we discuss hosting, access control, and data handling explicitly as part of scoping any real project, rather than applying one blanket policy to every client.
Client work stays anonymized unless we have explicit permission.
The real projects shown on our Projects page have had identifying details removed. We don't name clients publicly, use their logos, or share their data without direct permission.
Email and messaging.
Our business email (hello@anvilstack.co) runs on Zoho Mail. WhatsApp is used as a direct, optional contact channel for prospective and current clients — nothing sensitive should be shared over WhatsApp until a formal engagement and appropriate data-handling agreement is in place.
Being upfront about our current stage.
As a new studio, we don't currently hold formal security certifications (SOC 2, ISO 27001, etc.). If your project has specific compliance requirements, tell us during scoping — we'll be honest about whether we can meet them for your engagement, rather than claiming coverage we don't have.
Ask us directly.
Security and data-handling questions are a normal part of scoping a real project — raise them on the requirements call and we'll answer specifically, not with a generic policy page.