Security
How we protect your data and your account
🔒
TLS Encryption
All data encrypted in transit
🛡️
bcrypt Passwords
Passwords hashed with industry-standard bcrypt
🔑
JWT Auth
Stateless token-based authentication
Infrastructure Security
- All communications encrypted using TLS 1.2+ (HTTPS enforced)
- Servers hosted in SOC 2 Type II certified data centres
- Regular automated backups with point-in-time recovery
- Network-level firewalls and DDoS protection
- Separate production and staging environments
Application Security
- Passwords hashed using bcrypt with a minimum cost factor of 10
- JWT tokens with short expiry and secure rotation
- SQL injection prevention via parameterised queries
- XSS protection through output encoding and Content Security Policy headers
- CSRF protection on all state-changing endpoints
- Rate limiting on authentication and sensitive endpoints
- Regular dependency audits and automated vulnerability scanning
Account Security
You can take the following steps to protect your account:
- Use a strong, unique password (minimum 8 characters)
- Enable two-factor authentication (2FA) in Settings → Security
- Review active sessions and revoke any you don't recognise
- Never share your credentials with others
- Log out from devices you no longer use
Access Controls
- Role-based access control (RBAC) enforced at the API layer
- Principle of least privilege — staff access limited to what is necessary
- All internal access logged and audited
- Multi-factor authentication required for all admin accounts
Vulnerability Disclosure
We operate a responsible disclosure programme. If you discover a security vulnerability, please report it to [email protected].
Please include:
- A description of the vulnerability
- Steps to reproduce
- Potential impact
We will acknowledge your report within 48 hours and work to resolve confirmed issues promptly. We ask that you do not publicly disclose vulnerabilities until a fix has been deployed.
Incident Response
We maintain an incident response plan that includes:
- 24/7 monitoring and alerting
- Defined escalation procedures
- Prompt user notification for breaches affecting personal data
- Post-incident reviews to prevent recurrence
Compliance
Our security practices support compliance with:
- GDPR (EU General Data Protection Regulation)
- ISO 27001 principles
- OWASP Top 10 mitigations
Contact
Security concerns: [email protected]
General enquiries: [email protected]