Cloud Dimex marketing site
A thirteen-page marketing site shipped with a build-time Content Security Policy, consent-gated analytics and automated QA, scoring 100 for accessibility, best practices and SEO.
- When
- October 2026
- Context
- Cloud Dimex LTD, an AWS consulting company in Lagos
- Role
- Solo build
- Next.js
- React
- Tailwind CSS
- Three.js
- Vercel
- Web3Forms
- hCaptcha
- GA4
The problem
A cloud consultancy is judged on its own site. It had to load fast, pass a security review, and collect enquiries without leaking anything.
Security
- A Content Security Policy generated at build time with SHA-256 hashes for inline scripts and no unsafe-inline, plus a per-build nonce so the live-chat widget runs under the policy rather than around it.
- HSTS preload and a full set of security response headers.
- The contact form combines hCaptcha, a honeypot field and validation on both the client and the server.
Privacy and compliance
- Google Analytics only loads after the visitor accepts cookies.
- A privacy policy written against the Nigeria Data Protection Act 2023.
Quality
- Lighthouse mobile: 100 for accessibility, best practices and SEO on every page tested.
- WCAG AA contrast verified across all twenty colour pairs, and no horizontal overflow from 360px to 1440px.
- Playwright scripts check links, the CSP, the form, overflow and page metadata on every run.
- Search Console and Bing Webmaster Tools set up and the sitemap submitted.
The result
- Thirteen indexable pages live on a static export, indexed and monitored.
- Enquiries arrive through a form that is validated, rate-limited by captcha and free of unsafe-inline script.
Keep reading