Safety by design.
The current website is a read-only preview with no database, account login or live payment processing. Its security controls minimise attack surface now and define the minimum standard for future commerce functions.
Security baseline: 29 September 2026No website is “hack-proof”
Security is an ongoing risk-management process. GOZOLT must combine secure code, hardened hosting, restricted access, monitoring, tested recovery, independent assessment and rapid patching. This public preview is hardened, but it is not a certification of future back-end systems or payment compliance.
Current website controls
- Strict Content Security Policy with only first-party scripts, styles, images and fonts.
- Script integrity checks and no dynamically injected HTML.
- Clickjacking, MIME-sniffing, referrer and browser-permission restrictions.
- No analytics scripts, advertising trackers, embedded third-party maps or remote fonts.
- Read-only server methods and blocked execution of unexpected server-side scripts.
Current data handling
- Preview booking details are not transmitted or saved.
- Preview data is cleared when its dialog closes.
- No passwords, identity documents or card details are requested.
- External map access occurs only after a deliberate click.
Required production payment architecture
- Use a PCI DSS-validated payment service provider and provider-hosted payment page or equivalent hosted fields.
- Keep all raw card-number, expiry and CVV entry outside GOZOLT-controlled pages and servers wherever possible.
- Store only provider tokens and the minimum transaction metadata required for orders, refunds and accounting.
- Use TLS, strong customer authentication/3-D Secure where applicable, signed webhooks, replay protection and idempotency controls.
- Verify the applicable PCI DSS scope and Self-Assessment Questionnaire with the acquiring bank and payment provider before launch.
- Perform required external vulnerability scanning and payment-page change/tamper monitoring for the selected integration model.
Required account and API controls
- Multi-factor authentication for administrators and privileged supplier accounts.
- Least-privilege roles, server-side authorisation and separate production access.
- Strong password hashing, secure session cookies, rate limits and automated abuse detection.
- Strict input validation, output encoding, parameterised database queries and safe file-upload controls.
Required operational controls
- Managed secrets, encrypted backups and tested recovery procedures.
- Central security logs that exclude passwords, tokens, card data and unnecessary personal information.
- Dependency, infrastructure and container scanning in the release process.
- Independent penetration testing, patch targets and a documented incident-response plan.
Protect yourself
Never send GOZOLT a password, one-time code, full card number, CVV, bank login or identity document through ordinary email. Check that the address bar shows https://gozolt.com.mt before using a future live service.
Report a security concern
Use the contact details on the GOZOLT contact section. Do not include real customer records, card information or harmful exploit code. Provide the affected page, observed behaviour and safe reproduction steps.
Privacy and legal compliance
Security controls support—but do not replace—GDPR governance, lawful processing records, supplier agreements, retention schedules, data-subject request procedures and breach assessment. Read the Privacy & GDPR notice.
Back to website