Security
Last updated: 8 October 2026
We build software for clients, so we take the security of our own website seriously. This page explains how we protect it and how to report a vulnerability.
How we protect this website
- All traffic is encrypted over HTTPS, and requests pass through Cloudflare’s network protection.
- WordPress, our theme and our plugins are kept up to date, and unused plugins are removed.
- The administrator login is hidden, and features commonly abused by attackers (such as XML-RPC password attempts and public user lists) are disabled.
- Forms validate everything on the server and are protected against spam, automated submissions and email-header injection, with rate limits.
- Uploaded CVs are checked for file type and size and stored outside the public website folder, so they can’t be opened by URL.
- We take regular backups and test that they can be restored.
Reporting a vulnerability
If you believe you have found a security issue on zowatech.co, email [email protected] with the subject “Security report”. Please include the affected URL, what you found and the steps to reproduce it.
We ask that you:
- Give us reasonable time to fix the issue before sharing it publicly.
- Don’t access, change or delete data that isn’t yours, and stop as soon as you confirm the issue.
- Don’t run denial-of-service tests, spam, or social-engineering attempts against our team.
We will acknowledge your report, keep you updated, and credit you if you wish once the issue is fixed. Our machine-readable contact details are at /.well-known/security.txt.