Prepared for review: 30 September 2026. Status: draft, not effective.
1. The right scope
This overview distinguishes the marketing website from the separate HR application. It is not a certification, penetration-test report, service-level agreement or guarantee against incidents. Ask for verified product security information before entrusting the application with employee records.
2. Marketing-site controls supplied
The source includes server-side input validation, a fixed enquiry destination, HTML escaping in email content, request-body limits, same-origin checks, timeouts, basic in-process abuse controls and browser security headers. Secrets belong only in server-side environment variables. There is no employee database, payment form or file upload in this marketing project.
3. Privacy by default
Optional analytics starts only after opt-in and only when a valid measurement ID is configured. The site does not include advertising pixels or session recording. It never requests camera, microphone or precise location access. The currency service does not forward the visitor’s IP address to the exchange-rate provider. Mockups contain sample names and records only.
4. Hosting and production verification
The operator must select hosting, configure HTTPS and trusted proxy headers, protect origin access, verify email-domain ownership, configure a distributed rate limit and validate deployed headers. The provided in-memory limiter is not sufficient evidence of distributed abuse protection. Dependency installation, production build, deployment testing, vulnerability review and provider contracts remain launch checks.
5. Application evidence to request
For the separate HR product, verify tenant isolation, role-based access, administrator authentication, encryption and key management, auditability, backup and restore testing, deletion, support access, location and photo controls, incident handling and secure development. Document what is implemented and tested, by whom and when. Do not imply SOC 2, ISO 27001 or another certification unless a valid scoped report exists.
6. Sensitive attendance options
A photograph captured at check-in, continuous location tracking and biometric identification are different operations with different risks. The customer should assess necessity, legal basis, retention, who can access records and whether an alternative attendance method is appropriate. Features should not be marketed as universally lawful because they can be switched off.
7. Incident reporting
For a suspected website issue, contact info@staffworkspace.com with a short description and a safe way to follow up. Do not send passwords, employee records or full exploit payloads in an initial email. The owner must approve an operational reporting and escalation process before sensitive customer onboarding. This page does not promise an unstaffed 24-hour response service.
8. No unsupported promises
This build does not claim independently audited compliance, guaranteed data residency, zero downtime, a specific recovery time or universal payroll compliance. Such claims require operational evidence and contractual commitments. The final public security page must be kept aligned with the actual deployed website and separately verified application.