Security and data handling
Last updated 11 October 2026. Draft pending legal review.
We do not hold security certifications, and we will not imply that we do. This page explains the practical rules we follow.
This website
- All traffic is served over HTTPS.
- Contact-form submissions are validated on the server, rate-limited and checked for duplicates.
- No secrets or credentials are placed in browser code.
- The site sets no cookies and loads no third-party trackers.
Client deployments
- Each client’s data, credentials and configuration are kept separate.
- We request the minimum access a workflow needs, and document who owns each account.
- Secrets are stored on the server, never in browser code.
- Consequential actions — confirming bookings, sending money-related messages, changing records — require approvals you agree.
- Actions are logged so they can be reviewed.
- Customer data is not used to train AI models without explicit written permission.
- Offboarding removes our access and returns or deletes data as agreed.
Testing before go-live
Acceptance tests include unknown questions, malicious instructions hidden in documents, duplicate-action checks, failure and retry behaviour, usage limits and clean removal.
Reporting a problem
If you believe you have found a security issue, contact us through the contact form with “security” in the message. Please do not access data that is not yours.