Trust
Security practices
Transparent about platform security — without fake certifications.
Last updated: August 2026
Scope
This page describes security practices for the StudioBuild ordering platform and client portal. It is not a substitute for a penetration-test report, SOC 2 report or ISO certificate — StudioBuild does not currently publish those.
What we implement
Transport encryption (HTTPS), hashed account passwords, session-based authentication, role separation between public site, client portal and owner/admin tools, ownership checks on portal resources, rate limiting on sensitive auth paths, and production payment flows that fail closed when payment simulation is not explicitly allowed.
Customer data
Order, project and support data live in the platform so we can deliver and support your project. We do not sell customer data. Processors (payments, hosting, email, storage) are described in the privacy policy and listed on request.
Reporting a concern
If you believe you found a security issue affecting StudioBuild, email info@studiobuild.nl with enough detail to reproduce. Please do not include exploit payloads against production systems. We aim to acknowledge responsible reports on business days.
Honest limits
No public 24/7 SOC, no claimed ISO 27001/SOC 2, no enterprise SSO or SCIM in standard packages. Custom security requirements for larger projects can be discussed digitally — we only commit to what we can deliver.