Purpose and Scope
This Information Security Policy explains how MadeOfPixels Studio (“we”, “us”, “the Studio”) protects the confidentiality, integrity and availability of the information we handle. That includes client project data, personal information submitted through our website, source code, design assets and our own business records.
The policy applies to everyone who works on the Studio’s behalf, including founders, employees, freelancers and contractors. It covers every system, device, account and third-party service used to deliver our work, including the website madeofpixels.in.
Security Principles
Every security decision at the Studio is guided by the following principles.
- Confidentiality. Information is available only to the people who need it to do their work.
- Integrity. Data, code and deployed websites are protected against unauthorised or accidental change.
- Availability. Client websites and our working systems remain available and can be recovered quickly if something fails.
- Least privilege. Accounts and people receive the minimum access needed, for the minimum time needed.
- Security by design. Security is considered at the start of every project rather than added at the end.
- Reduced attack surface. We hand-code our sites and avoid unnecessary third-party code, so there is less to attack and less to patch.
- Continuous improvement. We learn from incidents and near-misses and update our practices accordingly.
Roles and Responsibilities
- Studio Management owns this policy, approves any exceptions, provides the resources needed to follow it, and leads the response to security incidents.
- Team members and contractors follow this policy, protect the credentials and data entrusted to them, complete security awareness activities, and report suspected incidents immediately.
- Clients are responsible for the security of accounts and credentials they hold themselves, and for telling us promptly if they suspect that any account shared with us has been compromised.
Information Classification and Handling
We sort information into four levels so that the right protection is applied to the right data.
| Level | Description and examples | Handling rule |
|---|---|---|
| Public | Information intended for release, such as published website content and client-approved portfolio work. | Protect integrity; no confidentiality restrictions. |
| Internal | Business information not meant for the public, such as internal planning, drafts and general project notes. | Share only within the Studio and with the relevant client. |
| Confidential | Client materials, contracts, quotes, unreleased designs, project source code and personal data from enquiries. | Need-to-know access; encrypted in transit; stored only in approved systems. |
| Restricted | Passwords, API keys, access tokens, private keys and any payment or government-identity data. | Held only in a password manager or secrets store; never in email, chat or source code; collected only where unavoidable. |
Access Control and Authentication
- Access is granted on a need-to-know, least-privilege basis and is tied to a named individual. Shared accounts are avoided.
- Passwords must be long, unique and generated and stored in a reputable password manager. Passwords are never reused across services.
- Multi-factor authentication (MFA) is enabled on email, source code hosting, hosting and deployment platforms, domain registrar and DNS accounts, and any other critical service that supports it.
- Access is removed promptly when a project ends, a contractor leaves or a role changes, and access rights are reviewed at least once a year.
- Credentials supplied by clients are received through secure channels, used only for the agreed work, and returned, rotated or deleted at handover.
Secure Design and Development
Every website and web application we build follows secure development practices from the first line of code.
- Sites are hand-coded from scratch. We do not rely on off-the-shelf themes, plugins or page builders, which are a common source of vulnerabilities.
- All source code lives in version control with a full change history. Changes are reviewed before they reach production.
- Secrets such as API keys and tokens are never committed to source code. They are held in the hosting platform’s environment settings or an equivalent secrets store.
- Third-party scripts and libraries are kept to a minimum, evaluated before they are added, loaded from reputable sources, and updated when security fixes are released.
- Where a project accepts user input, we validate it on the server side, encode output to prevent injection and cross-site scripting, and apply the OWASP Top 10 as a reference for common risks.
- Changes are tested on a preview deployment before going live.
Hosting, Network and Transport Security
- Our website is served from a managed hosting platform with a global content delivery network, which handles server patching, TLS certificates and infrastructure hardening.
- All traffic to madeofpixels.in is delivered over HTTPS. Sensitive information is never sent over unencrypted channels.
- Domain, DNS and hosting accounts are protected with MFA, and changes to DNS records are made deliberately by authorised people only.
- Domain registration and certificate renewals are monitored so that a lapse cannot interrupt or expose a site.
Data Protection and Privacy
We collect only the personal information needed to respond to enquiries and deliver projects: typically a name, email address, an optional phone number and the message you send us through our contact forms, plus aggregated usage data from website analytics.
- We collect personal data only for a specific, stated purpose, and we do not use it for unrelated purposes.
- We do not sell personal data.
- Personal data is retained only for as long as it is needed for the purpose it was collected for, or as the law requires, and is then deleted securely.
- We handle personal data in line with applicable Indian law, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023, as its provisions come into force.
You may ask us at any time what personal data we hold about you, and request that we correct or delete it. Write to hello@madeofpixels.in and we will respond within a reasonable time.
Third-Party Services and Vendors
We use a small number of established third-party services to run the Studio and this website. We choose reputable providers, review their security and privacy terms, share only the data a service needs, and remove access when it is no longer required.
| Category | Provider | Purpose |
|---|---|---|
| Hosting and CDN | Vercel | Serves madeofpixels.in over HTTPS. |
| Source code | GitHub | Version control and code backup. |
| Contact forms | Formspree | Delivers enquiries submitted through our website forms to our inbox. |
| Analytics | Google Analytics, Microsoft Clarity | Aggregated traffic and usage insight used to improve the site. |
| Web fonts | Google Fonts | Delivery of the typefaces used on our pages. |
These providers process data under their own terms and privacy policies. Where a project requires additional services, we tell the client which providers are involved.
Devices and Workspace Security
- Devices used for Studio work are protected with a password or biometric lock and an automatic screen lock.
- Full-disk encryption is enabled wherever the device supports it.
- Operating systems, browsers and development tools are kept up to date, and security updates are applied promptly.
- Only trusted software from reputable sources is installed, and built-in or reputable anti-malware protection is kept active.
- Public or untrusted networks are avoided for sensitive work; where unavoidable, a trusted VPN is used.
- A lost or stolen device is reported immediately so that sessions can be revoked and credentials rotated.
Backup and Business Continuity
- Source code is stored in remote version control, so every project can be rebuilt and redeployed from source.
- Client deliverables and design assets are kept in more than one secure location.
- Backups are protected by the same access controls as the original data, and restoration is tested periodically.
- If a service fails or a site is compromised, we restore client-facing sites first and as quickly as practicable, and keep affected clients informed.
Incident Response and Breach Notification
A security incident is any event that compromises, or could compromise, the confidentiality, integrity or availability of information or systems. Everyone working with the Studio must report suspected incidents immediately. We respond in six stages.
- Identify and reportConfirm what happened, when it was detected and which systems or data are involved.
- ContainLimit the damage by disabling affected accounts, revoking tokens and keys, and isolating compromised systems.
- AssessDetermine the scope, the data affected and the people or clients who may be impacted.
- Eradicate and recoverRemove the cause, restore clean systems and data from trusted sources, and verify normal operation.
- NotifyInform affected clients and individuals without undue delay, and report to authorities where required by law. This includes reporting qualifying cyber incidents to CERT-In within the timeframe set by its directions, and meeting the notification duties of the Digital Personal Data Protection Act, 2023 as they come into force.
- ReviewCarry out a post-incident review, record the lessons learned and put corrective actions in place.
We keep a record of every incident, its impact and the actions taken.
Responsible Vulnerability Disclosure
We welcome reports from security researchers and members of the public who find a vulnerability in madeofpixels.in. If you believe you have found one, please tell us so we can fix it.
Email hello@madeofpixels.in with the subject “Security Report”. Please include a clear description, the steps needed to reproduce the issue, the affected URL or component, and the impact you expect. Our machine-readable contact details are published in security.txt.
- We will acknowledge your report within three business days.
- We will investigate, keep you informed of progress, and tell you when the issue is resolved.
- We will credit you for the finding if you wish. We do not operate a paid bug bounty programme.
- We will not pursue legal action against anyone who reports a vulnerability in good faith and follows the guidelines below.
- Test only madeofpixels.in. Third-party platforms we use are out of scope and should be reported to their owners.
- Do not access, change or delete data that is not yours, and stop as soon as you have shown that the issue exists.
- Do not perform denial-of-service testing, spam, social engineering, phishing or physical attacks.
- Give us a reasonable time to fix the issue before you disclose it publicly.
Confidentiality and Client Data
- Client materials, credentials and business information are used only for the agreed project.
- We do not publish, share or reuse client work or data without the client’s consent.
- We are glad to sign a non-disclosure agreement before a project begins, on request.
- Confidentiality obligations continue after a project ends.
Awareness and Training
Most security incidents begin with human error, so awareness matters as much as technology. Everyone who works with the Studio is expected to read and follow this policy, to learn to recognise phishing and social engineering, and to review our security practices at least once a year.
Compliance, Monitoring and Review
We review this policy at least once every 12 months, and sooner after a significant incident, a change in the services we use or a change in applicable law. We check our own compliance through periodic reviews of accounts, access rights and configurations.
When the policy changes, we update the version number and the “Last reviewed” date at the top of this page.
Policy Violations
Failure to follow this policy may result in the removal of access, the termination of an engagement or employment, and, where the law requires or allows, legal action. Anyone who reports a concern in good faith will not be penalised for doing so.
Contact
Questions about this policy, requests about your personal data and security reports can all be sent to us using the details below.
MadeOfPixels Studio
Email Phone AddressVasai West, Maharashtra 401202, India
This policy describes the security practices and commitments of MadeOfPixels Studio. It is not a certification or an independent audit, and it does not by itself create a contract. Where a client agreement contains specific security terms, those terms apply in addition to this policy.