Cookie Policy
Exactly what this website stores on your device, and why.
1. The short version
This website sets one cookie. It is strictly necessary, it contains no personal information, it is not used to track you, and it is deleted when you close your browser. We run no analytics, no advertising pixels and no social media trackers on these pages.
2. What cookies are
Cookies are small text files placed on your device by a website. They are widely used to make sites work, to remember preferences, and — very often — to track behaviour across sites for advertising. Similar technologies include local storage, session storage and tracking pixels. This site uses none of those.
3. Cookies we set
| Name | Purpose | Type | Expires |
|---|---|---|---|
PHPSESSID |
Maintains your session so the contact form can be protected against cross-site request forgery, and so a validation message survives the page reload after you submit. Holds a random identifier only. | Strictly necessary | When you close your browser |
The cookie is set with the HttpOnly flag (so it cannot be read by scripts),
the Secure flag over HTTPS (so it is never sent unencrypted), and
SameSite=Lax (so it is not sent on cross-site requests).
4. What we deliberately do not use
We think a security consultancy should hold its own website to the standard it recommends to clients. So this site does not use:
- analytics of any kind, including Google Analytics;
- advertising or remarketing pixels;
- social media embeds or share widgets that phone home;
- third-party fonts, scripts or stylesheets loaded from external domains;
- fingerprinting, session recording or heatmap tools.
If we ever introduce analytics, we will update this policy and implement a proper consent mechanism before any non-essential cookie is set.
5. Third-party services
If you click through to book a consultation, you leave this website and arrive at our scheduling provider's platform. That provider will set its own cookies under its own policy, over which we have no control. No cookie from that provider is set while you remain on this site — the link is an ordinary hyperlink, not an embedded widget.
Our hosting provider may also operate infrastructure-level protections, such as a content delivery network or web application firewall, which can set a strictly necessary cookie for security purposes.
6. Managing cookies
You can control or delete cookies through your browser settings — every major browser offers this under its privacy or security preferences, and most offer a private browsing mode that discards cookies at the end of the session.
Blocking the session cookie will not stop you reading this website. It will prevent the contact form from submitting successfully, because the anti-forgery protection depends on it. If you would rather not accept the cookie, email us directly at sales@infosecgovernance.com instead.
7. Why we do not show a consent banner
Under UK and EU rules, consent is required before storing non-essential cookies. Cookies that are strictly necessary to deliver a service the user has requested are exempt. The only cookie we set falls within that exemption, so there is nothing here for you to consent to — and a banner would be theatre rather than protection.
8. Changes to this policy
We will update this page whenever our use of cookies changes, and revise the "last updated" date above accordingly.
9. Contact
Questions about this policy can be sent to sales@infosecgovernance.com. See also our Privacy Policy.