Skip to main content

Security Policy

Effective date: 21 July 2026

Security is not a department at Code Bunnies Ltd – it is how a two-person studio protects the businesses that trust us with their software. This page describes the practices we actually follow. We do not currently hold formal certifications such as ISO 27001; what follows is how we work, stated plainly.

Infrastructure and hosting

Data protection roles

Access control

Development practices

Client data

Backups and continuity

Incident response

If we become aware of a security incident affecting a client system or client data, we will contain it, investigate, and notify the affected client without undue delay – with a plain-language account of what happened, what was affected, and what we changed to prevent recurrence.

Reporting a vulnerability

If you believe you have found a security issue in our website or in a system we operate, please email info@codebunnies.com. We will acknowledge your report promptly, keep you informed as we investigate, and never take action against good-faith research.

Changes to this policy

We review this policy as our practices evolve and update the effective date above when it changes.