Website security
- All traffic is encrypted in transit (TLS) with HSTS enforced.
- Security headers are applied site-wide: frame, content-type, referrer and permissions policies.
- Forms are protected by server-side validation, rate limiting and spam filtering; uploads are type- and size-restricted.
- The website holds no customer database: submissions are relayed to a monitored inbox, minimising the attack surface.
Engagement security
- Rental and repaired devices are wiped using documented procedures before reuse; data-destruction certificates are issued per drive on request and always on disposal.
- Engineer access to client environments is scoped, logged and revoked at engagement end.
- Asset registers, service records and BOQs are handled as confidential client information.
Responsible disclosure
Found a vulnerability in this website? Email info@nvtechsol.com with the subject 'Security disclosure'. We acknowledge within 2 business days, will not pursue good-faith researchers, and will credit fixes on request. Please avoid accessing data that isn't yours and give us reasonable time to remediate before public disclosure.
Questions about this document? Write to info@nvtechsol.com with the document name in the subject line.
