Security

How we protect your data and your account

🔒

TLS Encryption

All data encrypted in transit

🛡️

bcrypt Passwords

Passwords hashed with industry-standard bcrypt

🔑

JWT Auth

Stateless token-based authentication

Infrastructure Security

  • All communications encrypted using TLS 1.2+ (HTTPS enforced)
  • Servers hosted in SOC 2 Type II certified data centres
  • Regular automated backups with point-in-time recovery
  • Network-level firewalls and DDoS protection
  • Separate production and staging environments

Application Security

  • Passwords hashed using bcrypt with a minimum cost factor of 10
  • JWT tokens with short expiry and secure rotation
  • SQL injection prevention via parameterised queries
  • XSS protection through output encoding and Content Security Policy headers
  • CSRF protection on all state-changing endpoints
  • Rate limiting on authentication and sensitive endpoints
  • Regular dependency audits and automated vulnerability scanning

Account Security

You can take the following steps to protect your account:

  • Use a strong, unique password (minimum 8 characters)
  • Enable two-factor authentication (2FA) in Settings → Security
  • Review active sessions and revoke any you don't recognise
  • Never share your credentials with others
  • Log out from devices you no longer use

Access Controls

  • Role-based access control (RBAC) enforced at the API layer
  • Principle of least privilege — staff access limited to what is necessary
  • All internal access logged and audited
  • Multi-factor authentication required for all admin accounts

Vulnerability Disclosure

We operate a responsible disclosure programme. If you discover a security vulnerability, please report it to [email protected].

Please include:

  • A description of the vulnerability
  • Steps to reproduce
  • Potential impact

We will acknowledge your report within 48 hours and work to resolve confirmed issues promptly. We ask that you do not publicly disclose vulnerabilities until a fix has been deployed.

Incident Response

We maintain an incident response plan that includes:

  • 24/7 monitoring and alerting
  • Defined escalation procedures
  • Prompt user notification for breaches affecting personal data
  • Post-incident reviews to prevent recurrence

Compliance

Our security practices support compliance with:

  • GDPR (EU General Data Protection Regulation)
  • ISO 27001 principles
  • OWASP Top 10 mitigations

Contact

Security concerns: [email protected]

General enquiries: [email protected]