Trust & Safety

Security Policy

How we keep your website, your customers' data, and your business safe.

When you hand your website over to us, you're trusting us with your customers' data, your ad accounts, and your reputation. We don't treat that lightly. Here's exactly how we protect it.

Every site is encrypted, by default

Every website we build runs on HTTPS with strict transport security enforced, so your visitors' connection is encrypted from the first click — no exceptions, no opt-in required. We also build in browser-level defences such as Content-Security-Policy and clickjacking protection, so your site is hardened against common attacks before it ever goes live, not patched up afterwards.

Only the right people get in

Every account with access to your site, domain, or hosting requires multi-factor authentication — a password alone is never enough. Access is need-to-know: the only people who can touch your site are the ones actively working on it, and every credential is stored in a password manager, never shared over email or chat.

Nothing is ever truly lost

Every deploy is versioned, so if anything ever goes wrong, we can roll your site back to the last working version in minutes. Where a site runs on WordPress, we also keep independent backups on a regular schedule, stored away from the live server, so a single point of failure can never take your whole site down for good.

If something happens, you hear it from us first

If we ever detect or suspect a security incident on your site, our priority is containing it and telling you — directly and promptly, not after the fact. Where customer data is involved and there's a real risk of harm, we follow Australia's Notifiable Data Breaches scheme, which sets out when the OAIC and affected individuals must be notified.

A lean, trusted toolkit

We only connect the third-party tools your site actually needs — think analytics, booking, and tag management — and nothing more. Every one of those providers operates under its own security obligations, and we don't bolt on integrations "just in case."

We don't negotiate with ransomware

If ransomware ever hit a site we manage, we would not pay. Paying funds further attacks and never guarantees your data back. Instead, we'd restore from backup, report the incident to the Australian Cyber Security Centre, and bring in a specialist — a stance we've committed to in advance so it's never a decision made under pressure.

Security is a habit, not a one-off

We review this policy every quarter and update our practices as new tools, threats, and standards emerge. Keeping your site secure isn't a box we tick once at launch — it's ongoing, for as long as we're looking after your site.

Talk to us

Questions about how we protect your site, or want to report a suspected security issue? Reach us at hello@ozmedia.digital — we take every report seriously and respond fast.

OZ Media Digital
Hornsby NSW 2077
hello@ozmedia.digital · +61 424 730 164 · WhatsApp