Security is not a feature we add at the end - it runs through how we build, host and operate every system we deliver. This page explains the safeguards protecting your data and how to report a problem to us.
Layered controls across infrastructure, application, people and process - so that a single failure never becomes a breach.
TLS 1.2+ for all data in transit and AES-256 encryption at rest for databases, backups and stored documents.
Role-based permissions on a least-privilege model, enforced multi-factor authentication, and quarterly access reviews.
Firewalled, patched servers in secure data centres with network segmentation and continuous availability monitoring.
Peer-reviewed code, parameterised database access, dependency scanning, and OWASP Top 10 checks before every release.
Automated daily backups with retention windows, periodic restore testing, and documented recovery objectives per service.
Background-verified staff, signed confidentiality agreements, security awareness training, and a defined incident response plan.
Our products are built on a hardened baseline: all database access is parameterised to eliminate injection, user input is encoded on output to prevent cross-site scripting, session cookies are issued with secure and HTTP-only flags, and administrative interfaces are separated from public surfaces. Uploaded files are validated by type and size, stored outside the web root, and served only through authenticated endpoints.
Production systems run behind firewalls with only required ports exposed. HTTPS is enforced across the estate with HTTP Strict Transport Security enabled, and TLS certificates are renewed automatically. Servers receive security patches on a scheduled cycle, with out-of-band patching for critical vulnerabilities.
Access to client environments is granted on a need-to-know basis, tied to a named individual, and revoked immediately on role change or exit. Shared credentials are not permitted. Privileged operations are logged, and administrative sessions require multi-factor authentication.
Personal and business data is encrypted at rest and in transit, segregated per client, and retained only as long as the engagement and applicable law require. Retention periods and deletion procedures are set out in our Privacy Policy. On contract termination, client data is exported in an agreed format and then securely erased.
Availability, error rates and authentication anomalies are monitored continuously. When an incident is detected we contain it, assess impact, notify affected clients without undue delay, remediate the root cause, and issue a written post-incident summary. Current platform availability is published on our status page.
Each managed service has a documented recovery point objective and recovery time objective agreed with the client. Backups are stored separately from primary systems, and restore procedures are tested periodically rather than assumed to work.
Third parties that process data on our behalf - hosting providers, messaging gateways, payment processors - are assessed before onboarding and bound by confidentiality and data protection obligations. A current list of sub-processors is available to clients on request.
Security is shared. We ask clients and users to keep credentials confidential, enable multi-factor authentication where offered, remove access for departed staff promptly, keep browsers and devices updated, and verify any unexpected request that appears to come from us before acting on it.
We welcome reports from security researchers and will not pursue legal action against anyone who reports a genuine issue in good faith and follows the guidelines below.
The affected URL, endpoint or product
Clear steps to reproduce the issue
Proof of impact - screenshots or request logs
Your name, if you would like to be credited
Access, modify or delete data that is not yours
Run denial-of-service or high-volume automated tests
Use social engineering or physical intrusion
Disclose the issue publicly before it is fixed