Website Security and Responsible Disclosure

How the website protects accounts, forms, customer data, uploaded files and integrations—and how security concerns can be reported responsibly.

Security approach

Security is a system responsibility—not a badge.

Public information explains the control areas without disclosing sensitive implementation details.

Account readiness

Account, recovery and two-factor interfaces remain feature-gated until the production identity service is configured.

Customer login

Data protection

Protected storage, access controls and retention rules must be verified in the production environment.

Privacy policy

Secure forms & uploads

Server validation, MIME checks, rate limits, private storage and optional malware scanning.

Data requests

Monitoring & audit

Server-side error logging is available; administrator audit logging will be enabled with the production administration system.

Report a concern
Responsible disclosure

Report a potential security vulnerability privately.

Do not test against customer accounts, disrupt services, access data or publish sensitive details before the issue is assessed.

Include in the report

  • Affected page or feature
  • Clear reproduction steps
  • Potential impact
  • Screenshots or technical evidence
  • A safe contact method for follow-up
Ready when you are

Need customer support instead?

Use the support page for booking, billing, warranty or service questions.

Security responsibilities

Protect customer requests, forms and website operations without making unsupported guarantees.

The website uses application, transport and configuration controls intended to reduce common risks. No internet service can promise that every attack, device compromise or third-party failure will be prevented.

Security reports should avoid including passwords, payment details or unnecessary personal information. Provide the affected page, observed behaviour, date and a safe way to reproduce the issue.

WhatsApp
WhatsApp