Creativenova Last updated: 1 Aug 2026
At Creativenova, we take the security of our clients’ data, our systems, and our website seriously. This page outlines the measures we have in place to protect information, and how to report a potential security issue to us.
If you have any questions about this policy, please contact us at hi@creativenova.com.
1. Vulnerability Reporting
If you believe you have discovered a security vulnerability affecting our website or systems, we encourage you to report it to us responsibly.
How to report: Please email us at hi@creativenova.com with as much detail as possible, including:
- A description of the vulnerability
- Steps to reproduce the issue
- Any relevant screenshots, logs, or proof-of-concept material
- Your contact details, so we can follow up with you
What to expect: We will acknowledge receipt of your report as promptly as we can and investigate the issue. We ask that you act in good faith, avoid accessing or modifying data that isn’t yours, and give us reasonable time to address any issue before disclosing it publicly. We’re happy to keep you updated on the status of any report you submit.
We do not currently operate a paid bug bounty program, but we’re grateful for responsible disclosure and will always acknowledge your help.
2. Data Protection
We take steps to protect data both while it is being transmitted and while it is stored:
- In transit: Our website is served over HTTPS/TLS, encrypting data as it travels between your browser and our servers. Any sensitive or confidential material shared with clients is sent and received using encrypted methods.
- At rest: Once a project is completed, project files are archived on an external hard drive, which is kept securely and is not connected to any public network when not in active use.
3. Compliance & Standards
Creativenova follows the current laws of the United Kingdom regarding data protection, including compliance with UK GDPR.
We also hold a Gold-level certification from Phished Academy, reflecting our ongoing commitment to security awareness and best practice across the business.
4. Account Security
To protect client accounts and internal systems, we follow these practices:
- Multi-factor authentication (MFA) is enabled on our accounts.
- Unique passwords are used for each client — passwords are never reused across accounts or projects, reducing the risk of any single credential compromising multiple clients.
We recommend clients and website users follow similar practices to protect their own accounts:
- Use a strong, unique password for every account (a password manager can help with this).
- Enable multi-factor authentication (MFA) wherever it’s available.
- Avoid reusing passwords across multiple websites or services.
- Be cautious of unexpected emails asking you to log in or share sensitive information.
5. Physical Security
Our workstations are located on private property that is locked and monitored by CCTV, helping protect physical access to devices and any data stored on them.
6. Scope
This policy covers our website (creativenova.co.uk) and the systems we use to deliver client projects. It does not cover third-party websites, tools, or services we may link to or use, which are governed by their own security policies.
7. Contact Us
If you have a security concern, question, or wish to report a vulnerability, please contact us at:
Creativenova Bristol, BS16 5UF United Kingdom Email: hi@creativenova.com