Security
Last updated: September 2026
Security at CoreWorks
CoreWorks Studio takes reasonable measures to protect its systems and information. This page describes our current approach in plain terms. It will grow more detailed as our infrastructure does — right now, this website is a static site with no user accounts, no database, and no payment processing, which keeps the attack surface intentionally small.
Data Protection
This website does not operate a backend server that collects or stores personal information. Where the site links to an email address or a mailto: action, your message is sent directly through your own email client — it is not transmitted through or stored by this website.
Access Control
Internal systems and accounts used to build and maintain CoreWorks Studio's work are access-controlled on a need-to-use basis. As the studio's infrastructure grows, this section will be expanded to reflect the specific controls in place.
Secure Development
We aim to follow reasonable secure-development practices: keeping dependencies current, avoiding unnecessary third-party code, and reviewing changes before they go live. This site currently uses no third-party analytics, tracking, or advertising scripts.
Software and Dependency Updates
Fonts and any other third-party assets used by this site are reviewed and updated periodically. We avoid pulling in dependencies we don't need.
Account Security
This website does not currently offer user accounts or logins. If that changes, this section will be updated to describe how account security — authentication, password handling, and related protections — is handled.
Data Minimization
We aim to only handle the information necessary for a given purpose. As noted above, this site is not currently configured to collect analytics, tracking, or account data at all.
Incident Response
Security practices are reviewed and improved as our technology and operations evolve. If we become aware of a security issue affecting this website or our systems, we will work to address it promptly.
Backups and Recovery
Source files and assets for this website are maintained with version history so the site can be restored if something goes wrong.
Third-Party Services
This site is built without third-party analytics, advertising, or tracking services. If that changes in the future, this page and our Cookie Policy will be updated to reflect it.
Responsible Disclosure
If you believe you've found a security issue affecting CoreWorks Studio's website or systems, we want to hear about it. Please report it to the email below rather than disclosing it publicly, and give us reasonable time to investigate and respond before sharing details elsewhere.
Do not include sensitive information in an initial security report. A general description of the issue and steps to reproduce it is enough for us to start investigating.
Security Contact
Report a security concern to security@coreworksstudio.com.
This page describes CoreWorks Studio's current, actual practices as a small studio running a static website. It does not claim any third-party security certification (such as SOC 2 or ISO 27001), compliance framework, or infrastructure guarantee unless explicitly stated above. This page should be reviewed and updated as the studio's systems and practices evolve.