Skip to content
Nametech Canada

Website security hardening for small businesses in BC

A website security review with example data: what a bakery's site showed strangers and how each item was locked or removed, the locks tested from outside as a stranger, and a record of every change

A small business website takes enquiries, bookings and sometimes payments, and anyone on the internet can reach it. Website security hardening means finding what a stranger can reach that they should not, closing it, and proving it is closed. We do this for businesses in Surrey, across the Lower Mainland and elsewhere in Canada, on WordPress sites and on the custom websites and software we build.

We hold our own work to it first. NameCRM, the CRM our business runs on, went through a three-part sweep of access, rendering and the data layer that closed 25 findings in one day, each one verified from outside. Our own website's forms went through the same kind of pass, and on a client's WordPress site we found plugin endpoints that could change pages without anyone signing in, locked every one to administrators, tested the lock as a stranger would and checked that nothing had been tampered with.

Every change is written down with how to undo it, so you always know what was done to your site and why. The work starts with a free assessment, and the scope and estimate come in writing before anything on your site is touched.

What we have built

The security we built into our own software

Every line here is live in NameCRM, the CRM our own business runs on, or in iFloor, the system a Richmond flooring store runs on every day. Each is taken from the product itself, and the same habits go into every website we lock down.

findings closed in one day by a three-part security sweep, each verified from outside
25
test cases proving each role can do the same in the browser and on the server
588
database tables where two-step sign-in is enforced
57
days each nightly backup is kept, with a written restore runbook
30

Counted on September 30, 2026, from the products' own code and test records.

In NameCRMThe CRM we built and run our own business on

See NameCRM
  • NameCRM

    Swept the way an attacker looks

    A three-part sweep of access, rendering and the data layer closed 25 findings in one day, each verified from outside, and security headers now refuse clickjacking.

    How NameCRM protects your data
  • NameCRM

    Every route probed as a stranger

    Owner, admin, staff and viewer roles map to 14 capabilities, proven equal in the browser and on the server across 588 test cases, and every server route was probed as a stranger.

  • NameCRM

    Locked inside the database

    Every business table and file store is locked by row-level security in the database itself, so the app's own checks are a second layer, not the only one.

  • NameCRM

    Two-step sign-in, enforced

    Once enrolled, an authenticator code is required at every sign-in, enforced by the database on 57 tables and by the server, not just the login screen.

  • NameCRM

    Forms that stop bots

    Public forms combine a hidden trap field, a minimum fill time, a server-signed token, a small proof of work, first-party origins and a limit per visitor.

  • NameCRM

    Outside logins sealed

    Every stored connection to Microsoft, Google and QuickBooks is encrypted at rest with AES-256-GCM, and a gate refuses code that would store one unsealed.

  • NameCRM

    A second review before risky changes

    Changes touching money, sign-in or client data get an independent adversarial review before release, and every finding is checked in the code before it is fixed.

  • NameCRM

    Backups every night

    A snapshot of every business table goes to private storage each night and is kept 30 days, with a Back up now button and a written restore runbook.

  • NameCRM

    Only running code is served

    Production serves only the files the app runs, so internal documents, tests and registries are never reachable on the web.

In iFloorThe system a Richmond flooring store runs on every day

See iFloor
  • iFloor

    Callbacks checked before they are trusted

    Callbacks from the phone and email providers are checked for a valid signature before they are trusted, and every failure is logged.

  • iFloor

    AI tools nobody outside can spend

    The card and order scanners need a staff sign-in, are rate limited and cap upload size, so nobody outside can spend the store's AI budget.

  • iFloor

    Departed staff locked out everywhere

    Each person sees the devices signed in to their account, and deleting an account signs that person out everywhere, so an old login opens nothing.

See every feature behind our Website Security work44 of the 433 live features of NameCRM and iFloor prove this service. The full list opens filtered to them, one sentence each.Browse the 44

How we work

How we lock a website down

The team behind Nametech has built websites and software since 2014, and Nametech Canada Ltd. was incorporated in 2025. Security work follows the same steps on every site, from one WordPress plugin to a custom app.

Book a Free Assessment
  1. Free assessment

    Thirty minutes on what your site does and who signs in to it. Before the call we look at what it shows strangers: forms, plugins, admin pages and software versions.

  2. Scope in writing

    A written list of what we found and what we will change, with an estimate. Nothing on the site is touched until you approve it.

  3. Back up, then lock

    A full backup first. Then each open door is locked to the people who should use it, or removed, and every change is noted with how to undo it.

  4. Test as a stranger

    Each lock is tested from outside the way a stranger would try it, and your own sign-ins and forms are tested to make sure they still work.

  5. A written record

    You get the record: what was open, what we changed, what we checked for tampering and what to watch next.

Related Services

Explore our related services

All web and marketing services

Custom CRMs with client portals, e-signature, QuickBooks and Stripe built in.

CRM pipeline from lead to won

FAQ's

Frequently asked question

What does website security hardening include?

We start with what your site shows strangers: forms that accept anything, plugin or API endpoints that change content without a sign-in, admin pages left open and outdated software. Each is locked or removed, tested from outside the way a stranger would try it, and written down with how to undo it.

Have you locked down a WordPress site that was already exposed?

Yes. On a client's WordPress site we found plugin endpoints that could change pages without anyone signing in. We locked every one to administrators, confirmed from outside that strangers were refused, and checked users and settings for signs of tampering. None were found, and the rest of the plugin's work, which the site relied on, kept running.

How do you protect the forms on a website?

The forms in NameCRM, the CRM we built, combine a hidden trap field, a minimum fill time, a signed token, a small proof of work and a limit per visitor. We put our own website's forms through the same pass: the contact form refuses requests from other websites and checks each token before anything reaches our CRM.

What if someone has already changed my site?

We find out what changed before we change anything: the site's revision history, its users and its settings, and any edit that did not come through the editor. The last good version is restored, the way in is closed and tested from outside, and you get a written account of what we found and did.

How do you secure the software you build for us?

The way we secured our own. In NameCRM, access rules live in the database itself, every server route was probed as a stranger, roles were proven equal in the browser and on the server across 588 test cases, and changes touching money, sign-in or client data get an independent review before release.

Do you keep backups?

Before we change a live site we take a full backup, so any change can be undone. In NameCRM, the CRM we built, a snapshot of every business table goes to private storage each night and is kept 30 days, with a written runbook for restoring it. Backups are part of the work, not a separate service.

Do you hold a security certification?

No, and we do not claim one. What we offer is the practice: find what a stranger can reach, lock it, prove the lock from outside and write down what changed. If you need a formal penetration test or a compliance audit, use an accredited firm, and we can fix what it finds.

What does website security work cost?

It depends on what the site exposes and how it is built. Locking down one WordPress site is smaller work than reviewing a custom app with sign-ins and payments. We publish no flat price; after the free assessment you get a written estimate before any work starts.