Skip to content
cpf.digital

about

Websites that get tested like software.

CPF Digital is one person — me, Connor Flynn. By day I’m a QA engineer at a cybersecurity company, where my job is finding what’s broken in software before it ever reaches a customer. CPF Digital is where that discipline meets the web: a deliberately small studio building sites for trades and small businesses that deserve better than they usually get.

I build with modern AI-assisted tooling — I’m not going to claim I hand-type every line to prove a point. What actually matters, and what doesn’t change, is the QA discipline: nothing ships until it’s been tested properly, not just eyeballed and hoped for.

That discipline was built across a run of quite different industries: cybersecurity, regulated gambling software, telecoms and network hardware, and secure software escrow. Different products, different rules, different ways for something to go wrong — which is a large part of why I catch things a single-industry background wouldn’t think to check for.

Being small isn’t a stage this studio is trying to grow out of. It’s the product. No account managers, no handoffs, no “the developer who built your site has left the agency.” You talk to the person doing the work — at the quote, during the build, and in two years when you need something changed.

connect on linkedin →

what that means in practice

The QA mindset, applied to your website.

Journeys, clicked through end to end

Before launch, every path a customer can take gets walked: every form submitted, every link followed, every booking made. If it can break, I want to be the one who finds it.

Checked at every screen size

Your customers aren't on a designer's monitor. Sites are checked across breakpoints and connection speeds, then verified on a real phone before you ever see a launch date.

Performance as a budget, not a hope

Speed targets are set at the start and checked against Core Web Vitals before launch — because a slow site quietly costs you customers who never mention it.

Accessibility as standard

Semantic markup, keyboard navigation, proper contrast. Partly because it's right, partly because it overlaps almost perfectly with what search engines reward.

Security basics, done properly

TLS, security headers, sensible form protection, no exposed admin routes. The unglamorous stuff that working in cybersecurity makes impossible to skip.

Straight answers

If something is outside my lane, or a cheaper option would serve you better, I'll say so. A recommendation you can't trust is worthless.

Have a project in mind?

Tell me what you’re trying to do. I’ll tell you honestly whether I’m the right fit — and exactly what it would cost.