WSS
Web Specification Studio Home

Trust

How we secure our public website, verify our technical practices, and make those results independently verifiable.

Trust is earned through transparent technical practices rather than marketing claims. This page documents the current security posture of our public website, the practices we follow, and the independent assessments anyone can verify.

Last reviewed August 2026

Independent assessments

The public configuration of our website is periodically evaluated using recognised independent assessment services.

AssessmentCurrent ResultVerification
Mozilla HTTP ObservatoryA+ (125/100)View report ↗
Qualys SSL LabsA+View report ↗
ImmuniWeb Website SecurityAView report ↗

These assessments are performed by independent third-party services and reflect the public security configuration of our website at the time of testing. Results may change as standards evolve and assessments are periodically repeated.

ImmuniWeb Website Security Test

Official ImmuniWeb Website Security Rating.

Security practices

Our public website currently implements modern web security practices including:

  • HTTPS by default
  • TLS 1.3
  • HTTP Strict Transport Security (HSTS)
  • Content Security Policy (CSP)
  • X-Content-Type-Options
  • Referrer Policy
  • Permissions Policy
  • DNSSEC
  • Certificate Transparency
  • Secure HTTP response headers
  • Cloudflare edge protection
  • Routine dependency maintenance and updates

Client confidentiality

Technical rigor extends to how we handle client intellectual property. When you hire Web Specification Studio, your proprietary code and data remain strictly confidential.

  • Strict NDAs: We are happy to sign and adhere to strict Non-Disclosure Agreements before reviewing any proprietary repositories.
  • No Offshoring: All code review, performance auditing, and architectural work is done in-house. We do not offshore your code to unverified third parties.
  • No AI Training: We never use your private code or data to train public generative AI models.
  • Secure Access: We follow principle of least privilege, requiring only the repository access strictly necessary to complete the engagement.

Responsible disclosure

If you believe you have identified a security issue affecting Web Specification Studio, please report it responsibly.

We encourage responsible disclosure and will review legitimate reports promptly. Please do not publicly disclose vulnerabilities before they have been investigated and resolved.

Standards and transparency

We believe technical claims should be independently verifiable wherever possible. Where public assessment tools exist, we publish our results and link directly to the original reports rather than reproducing or summarising them.

What these assessments mean

Independent assessments provide confidence that our public website follows recognised browser and transport security best practices.

These assessments help verify the configuration of our public-facing infrastructure, including HTTPS, TLS configuration, HTTP response headers, and related security controls.

However, they do not guarantee that software is free from vulnerabilities, nor do they replace secure software development, code review, dependency management, monitoring, or ongoing maintenance.

Security is a continuous process rather than a single certification.

Continuous improvement

We regularly review our infrastructure, dependencies, deployment processes, and public security configuration to align with evolving web standards and recognised security best practices.

Where improvements can be made, they are incorporated into our normal technical workflow.

Revision history

This page reflects the current public security posture of Web Specification Studio.

If our security practices, verification process, or independent assessments materially change, this page will be updated and the revision date above will be revised accordingly.

See what's possible.

A deeper look at your website's security, accessibility, performance, and infrastructure.

Explore audits →