ClearAgency Writing Apply
Trust · Security & data

Built to be hard to break

Security is part of the work we sell, so we hold this site to the same standard we deliver for clients.

HTTPS onlyBank-grade hardeningNo third-party trackersGated client areas

Last updated 24 September 2026

01 In one line

This site is served only over HTTPS, ships a strict content-security policy and the full set of protective headers, stores almost nothing about you, and keeps every client document behind its own password.

02 Encryption in transit

Every request is served over HTTPS, always. A modern browser refuses to connect to this site over an unencrypted link before it ever sends a request — even the very first time — and anything that tried to load insecurely is upgraded automatically rather than fetched in the clear.

03 The browser hardening

A response is only as safe as the instructions it gives the browser. Every page here carries the full set, on purpose.

Taken together, these harden this site to a bank-grade standard: injected or third-party code cannot run, and the site cannot be framed or hijacked into acting against you. It is the same standard we hold our own to.

04 Where your data lives

The safest data is the data you never collect, so we start there. Reading this site sets no cookies, stores no IP address and runs no third-party tracker — the privacy notice lists every field we hold, field by field, taken from the code.

What little there is sits in an isolated store reachable only by this site’s own code. There is no public database endpoint to attack, and nothing is shared with a third party.

✓No Google Analytics or third-party analytics product.
✓No advertising, remarketing or cross-site tracking tags.
✓No stored IP addresses — visits are counted with a one-way hash that rotates daily and is never written to your device.

05 Who can get in

  • Client materials. Any presentation or proposal we prepare for a client is protected by its own password. A link on its own opens nothing. Viewers of a client deck must first agree to keep it confidential, and every sign-in is recorded — time, IP address, browser — so we can see who opened it (details).
  • Our own workspace. The tools we run the business with sit behind a strong, multi-factor sign-in, so a stolen password on its own is not enough to reach anything.
  • The contact form. A privacy-preserving check confirms a real person, not a script, is submitting it, without profiling you.

We keep the specifics of how each of these is built to ourselves. The point you can rely on: nothing that is meant to be private is reachable without the right credentials.

06 Reporting a problem

If you believe you have found a security issue on this site, please tell us at dj@clearagency.ai before disclosing it publicly. Describe what you found and how to reproduce it, and we will acknowledge you and keep you posted while we fix it.

In return, please test considerately: no automated vulnerability scans, no load or denial-of-service testing, and nothing that could reach or disrupt another person’s data. Good-faith research reported this way is welcome.

07 Contact

Anything about the security of this site, or a disclosure: dj@clearagency.ai. A real person answers.

See also: the privacy notice (every field we hold and why) and the terms of use.