In short
A custom website is a corporate site coded from scratch around the company’s needs instead of a ready-made theme or page builder. It is for companies whose requirements for speed, technical SEO, multiple languages or system integration don’t fit off-the-shelf tools. CybUP handles design and development together, building in Core Web Vitals, structured data, accessibility, security headers and KVKK cookie consent from the first release.
Custom website vs ready-made theme: what is the difference?
A custom website is one whose page structure, code and content model are written from scratch for your business; a ready-made theme is a template designed in general terms to suit thousands of sites. A theme gets you off the ground quickly, but the plugins loaded for every eventuality, the unused styles and the scripts all weigh the site down. Sooner or later a request like “can this section work differently?” runs into the limits of the theme.
Not every company needs a custom site. For a brochure site of a few pages that rarely changes, an off-the-shelf solution may be enough, and we will tell you so. A custom site makes sense for companies that expect to win customers through search, publish in more than one language, need the site to talk to a CRM or internal systems, or have firm requirements on speed and security.
Why does speed matter for a corporate website?
How fast a page loads directly affects whether visitors stay and how its page experience is judged in search results. According to the Core Web Vitals definitions on Google’s web.dev, a good experience means the largest content element (LCP) appears within 2.5 seconds, interaction responsiveness (INP) is 200 milliseconds or less, and layout shift (CLS) is 0.1 or less. The threshold is the 75th percentile of page loads, measured separately for mobile and desktop.
You hit those numbers through architecture, not through optimisation bolted on afterwards. We serve pages as pre-rendered static HTML wherever possible, deliver images in modern formats at the right size, keep web fonts to a minimum and load only the JavaScript each page actually needs. We measure in the lab before launch and track real-user data after it.
“Largest Contentful Paint (LCP): measures loading performance. To provide a good user experience, LCP should occur within 2.5 seconds of when the page first starts loading.”
How do you set up technical SEO and structured data?
Technical SEO is the groundwork that lets search engines crawl your site, understand each page correctly and work out which page answers which query. A clean URL structure, a single meaningful title per page, canonical URLs, an XML sitemap, correct redirects and sensible internal linking are all part of it. On a custom site these are built into the templates rather than left for an editor to remember.
Structured data tells search engines what a page is about in machine-readable form. Google’s structured data documentation recommends the JSON-LD format. We mark up organisation details, services, FAQs and content authors in JSON-LD. The same explicit structure also helps AI-powered search tools quote the information on your site accurately.
How should a multilingual corporate website be built?
On a multilingual site each language should live at its own URL, and the versions should point to one another with hreflang annotations. Google’s documentation on localised versions says each language version must list itself as well as all the others, and the links must be reciprocal; otherwise the annotations may be ignored.
Say an Istanbul-based machinery manufacturer is going to publish in Turkish, English and Arabic. Arabic reads right to left, so its layout is designed separately, and product names and technical tables are held in separate fields for each language. Instead of machine-translated pages nobody has checked, we set up a content workflow in which a person signs off every translation.
How do you make a corporate website accessible and secure?
For accessibility we work to the W3C’s WCAG 2.2 guidelines at level AA, the usual target for corporate sites. Keyboard navigation, sufficient colour contrast, descriptive alt text on images, labelled form fields and a correct heading hierarchy are the foundations. They help disabled users, and they also help search engines understand the page.
On security, alongside HTTPS we configure the response headers that give browsers extra protective instructions. The main ones recommended in the OWASP HTTP Headers Cheat Sheet are Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy and Permissions-Policy. A mostly static architecture already shrinks the attack surface; for dynamic parts such as forms and API endpoints we may recommend a WAF.
- Content-Security-Policy limiting which sources may load
- HSTS so the site is reachable only over HTTPS
- Server-side validation and bot protection on forms
- Removal of headers that reveal server and software versions
“Following these guidelines will also often make web content more usable to users in general.”
How should a website handle KVKK and cookie consent?
Non-essential cookies and tracking tools should not run until the visitor has made a choice. The Cookie Practices Guide published by the Personal Data Protection Authority (in Turkish) covers cookie types and when explicit consent is required under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698). We wire analytics and advertising tags so that they don’t load until the visitor consents.
Contact forms collect personal data too. We ask only for the fields that are needed, link to the privacy notice, and send submissions to a secure store or straight into your CRM rather than passing them around as plain-text email. The legal wording is for your KVKK adviser to decide; we build the technical implementation. For the technical side in more depth, see KVKK technical measures.
How does a custom website project run?
The project starts by pinning down who the site is speaking to, what it needs to say and what you want visitors to do. Will service pages bring in customers, or a product catalogue, or dealer applications? Once the goal and the page list are clear, content structure, design and code follow in that order. Writing the copy first lets the design take shape around the content, which works far better than filling empty boxes with text afterwards.
Before launch we check speed, accessibility, structured data and security headers. If you are moving from an existing site, we map every old URL to its new address; skip that step and you lose search traffic. Form enquiries can feed straight into your CRM. The initial review and quote are free.
What you receive
- A corporate website designed and coded specifically for your company
- A performance report measured against Core Web Vitals targets
- Sitemap, canonical URLs, redirects and JSON-LD structured data
- A multilingual structure with hreflang, where needed
- An interface checked against WCAG 2.2 AA
- Security headers, consent-based cookie management and form security
- A document explaining how to edit and publish content
How we work
- 1
Free review
We look at your goals, current site, the searches you compete on and integration needs, then prepare a written quote.
- 2
Content structure
The page list, URL structure, keyword mapping and copy plan are drawn up.
- 3
Design
Mobile and desktop designs are produced with real content and submitted for your approval.
- 4
Development and checks
The site is coded, then tested for speed, accessibility, structured data and security.
- 5
Launch and monitoring
The site goes live with redirects in place and search engines notified; the data is watched closely over the first weeks.
Frequently asked questions
Will we be able to update the website ourselves?
Yes. For content that changes often we set up a simple content management system, so you can edit news, products or case references without technical knowledge. Areas that could break the design or structure stay locked.
Do you provide hosting?
No, we don’t sell hosting. We deploy the site to the hosting provider you choose, or to a cloud account opened in your name. We recommend the option that suits the site’s architecture.
Will we lose our current search rankings?
With a properly handled migration, losses are kept to a minimum. Every old URL is listed and permanently redirected to its new equivalent, and errors in Google Search Console are watched after launch. Some fluctuation in the first weeks is normal.
How long does a custom website take to launch?
It depends on the number of pages and languages, the integrations and whether the content is ready. The most common cause of delay is copy and images arriving late. After the review we give you a phased timeline.
How much does a custom website cost?
We send a written quote once we have reviewed the scope; the review is free. The quote lists design, development, content and ongoing maintenance as separate items.
Do you offer support after launch?
Yes. Under a maintenance contract we handle security updates, backups, small changes and performance tracking. We agree the scope based on how the site is built.
Will our company email be affected?
No. Email records are preserved when the domain’s DNS records are changed. During the move we also check that the SPF, DKIM and DMARC records are correct; if email security needs attention in its own right, see our email security service.