Back to Home

Content Security Policy

Last updated: May 26, 2026

1. Introduction

Design & Marketing Services Group is committed to maintaining a secure and safe online environment for our users. This Content Security Policy (CSP) outlines the measures we have implemented to protect against certain types of web-based attacks, including cross-site scripting (XSS) and data injection attacks.

2. What is Content Security Policy?

Content Security Policy is a security standard that helps prevent malicious scripts from running on our website. It works by restricting the sources from which content can be loaded and executed, providing an additional layer of protection against security vulnerabilities.

3. Our CSP Implementation

3.1 Trusted Content Sources

Our website only allows content to be loaded from the following trusted sources:

  • Our own domain (designandmarketingservices.com)
  • HTTPS secure connections only
  • Approved third-party services for analytics, marketing, and functionality
  • Google Fonts for typography
  • CDN services for assets

3.2 Restricted Content

We restrict or block:

  • Inline scripts (scripts embedded directly in HTML)
  • Unsigned or untrusted scripts
  • Content from untrusted external sources
  • Unsafe inline styles and scripts
  • Plugins and Flash content

4. Approved Domains and Services

Content and resources are permitted from the following approved services:

  • Google Analytics and Google Tag Manager
  • Google Fonts
  • Stripe (for payment processing)
  • Cloudflare (CDN and security)
  • Base44 services and integrations
  • Essential third-party widgets and tools

5. CSP Headers

Our website implements CSP through HTTP headers. These headers instruct browsers to enforce content restrictions automatically. Our CSP headers include directives for:

  • default-src: Default fallback for all content types
  • script-src: Which domains can execute JavaScript
  • style-src: Which domains can provide stylesheets
  • img-src: Which domains can provide images
  • font-src: Which domains can provide fonts
  • connect-src: Which domains can be connected to
  • frame-ancestors: Which domains can embed our site

6. Security Benefits

Our CSP provides protection against:

  • Cross-site scripting (XSS) attacks
  • Data injection attacks
  • Clickjacking attacks
  • Unauthorized data exfiltration
  • Malicious plugin injections

7. User Impact

In most cases, our CSP will have no noticeable impact on your browsing experience. However, some scenarios may occur:

  • Some third-party extensions may not function properly
  • Browser console may show CSP violation warnings (these are non-critical)
  • Some embedded content from non-approved sources may not load

If you experience issues browsing our site, please clear your browser cache and cookies, or try a different browser.

8. Compliance and Standards

Our CSP implementation follows:

  • W3C Content Security Policy Level 3 recommendations
  • OWASP security best practices
  • Industry security standards for web applications
  • GDPR and privacy compliance requirements

9. Monitoring and Updates

We continuously monitor our CSP for:

  • Violation reports and potential security threats
  • Required adjustments for new features
  • Changes in security best practices
  • Compatibility issues with legitimate services

Our CSP may be updated periodically to maintain optimal security without impacting functionality.

10. Reporting CSP Violations

If you notice CSP-related issues or security concerns, please report them to:

Email: security@designandmarketingservices.com
Phone: (905) 123-4567

Please include details about the issue, your browser, and steps to reproduce if possible.

11. Questions and Support

If you have questions about our Content Security Policy or experience issues related to CSP, please contact our support team. We're here to help ensure you have a secure and seamless experience on our website.

Security Notice

If you discover a security vulnerability on our website, please report it responsibly to security@designandmarketingservices.com rather than publicly disclosing it. We appreciate responsible disclosure and will work with you to resolve any security issues promptly.