Skip to content
ZTech

Security and compliance

Secure, accessible and privacy-friendly by default

Every ZTech website is checked against WCAG 2.2 AA, ships with security headers and an accessibility statement, loads no non-essential tags before consent, and is hosted on UK or EU infrastructure with backups we test-restore. We build to standards. We do not issue legal compliance guarantees.

On every site

What every website gets

Accessibility

Checked against WCAG 2.2 AA, with an accessibility statement on your site. A written audit and fix report is also available for £295.

Security headers

Browser security headers are set at the host, plus SSL, so your site is harder to tamper with and visitors see the padlock.

Consent first

No non-essential tags, such as analytics or advertising, load before a visitor agrees. This matches the ICO's cookie guidance.

UK and EU hosting

Client websites and personal data are hosted on UK or EU infrastructure by default.

Backups that work

Daily offsite backups, test-restored before launch, because a backup you have never restored is only a hope.

Data processing agreement

A DPA comes with every care plan, so it is written down what we do with personal data for you.

Online shops

Extra care for shops: payment page scripts

If you take card payments, PCI DSS v4 asks merchants to control the scripts that run on payment pages. We keep an inventory of those scripts, allow only the ones needed, and watch for unexpected changes. Read the PCI Security Standards Council update.

Shops run on Shopify, in your name, so the card details are handled by the payment provider and not by your own website. Your exact PCI obligations depend on your payment provider and acquirer, so we help you gather the evidence and ask them to confirm.

Honest limits

We build to standards, we do not issue legal guarantees

FAQ

Security and compliance questions

Will my website be accessible and GDPR-friendly?

Yes, by default. Every site is checked against WCAG 2.2 AA, gets an accessibility statement and privacy pages, loads no tracking before consent, and is hosted on UK or EU infrastructure. We do not claim any site is "fully compliant", because that depends on your content too, but we build to the standard and show you the checks.

What we check on every site

Do you guarantee my website is legally compliant?

No. We build to recognised standards and test against them, but we do not issue legal compliance guarantees, and nobody can honestly promise that a site meets every law. For legal advice, speak to a qualified solicitor.

Will my site set cookies before visitors agree?

No. We do not load non-essential tags, such as analytics or advertising, before consent. Strictly necessary cookies are the only exception.

What do you do for online shops and card payments?

Shops run on Shopify, in your name. We follow PCI DSS v4 guidance for payment pages: we keep a list of the scripts on checkout pages, authorise them, and watch for changes.

Want to know how your site measures up?

Request a free audit, or book a call and ask us anything.