HomeSecurity

Security is priority one. Every layer, from the first commit.

Your ledger, your customers and your payroll live here, so protection is built in and verified live, never bolted on later.

HTTPS everywhere

Every page, API and document link is served over TLS with HSTS. Plain HTTP only redirects.

Security headers

Strict transport, no-sniff, frame denial, referrer and permissions policies, and a locked-down content policy.

Brute-force protection

Escalating per-IP lockout, per-account throttling and constant-time credential checks so accounts cannot be enumerated.

Bot classifier

Scanners, scrapers and raw HTTP tools are refused site-wide and banned on repeat. Search and social crawlers are allowed. No bot ever reaches the admin.

Spam defence on every form

Honeypot fields, minimum-fill-time tokens, rate limits, small body limits and link-spam detection on every public form and on login.

Probe banning

Requests for .env, .git, wp-login and similar are logged and the address is banned at the application and firewall.

Encrypted secrets

Payment gateway and AI keys are encrypted server-side and never sent to the browser. Secrets are generated on the server, never shared in chat.

Backups and self-healing

Daily backups with tested restores, and a liveness probe that restarts a hung process before anyone notices.

Data hosting and access

Data is hosted in secure European data centres, encrypted in transit and at rest and backed up daily. Every user gets only the permissions their role allows, every action is audited and customers reach only their own portal.

  • Role-based access with eight built-in roles
  • Server-side sessions, httpOnly cookies, 2FA for owners and admins
  • Full audit trail of who changed what and when
  • Bring your own AI key: your data never trains anyone's model
Secure operations
UPTIME, LAST 90 DAYS99.98%Self-healing probe active

Questions about security?

Talk to us about compliance, residency or a security review.

Contact us