+44 7418 606768
Client Login

Security

How we protect accounts and data, described plainly enough to be useful.

How we store passwords

Passwords are hashed with Argon2id, the current recommended algorithm, using parameters tuned so that each verification is deliberately slow. We never store a password in a form we could read, which is also why we cannot tell you what your password is — only reset it.

Transport and headers

Every connection is HTTPS with HSTS preloaded. We ship a strict Content Security Policy, a frame-deny header and a referrer policy that stops full URLs leaking to third parties.

Bot and abuse protection

Public forms run two independent challenges — Cloudflare Turnstile and Google reCAPTCHA — and both must pass. Sign-in attempts are rate-limited per IP, and repeated failures lock the route temporarily rather than letting an attacker grind through passwords.

Access and monitoring

Sensitive administrative actions require a password re-entry even for an already signed-in administrator. Every sign-in, failed attempt, link creation and settings change is written to a security log we review.

What we ask of you

  • Use a password you have not used anywhere else
  • Sign out on shared devices rather than closing the tab
  • Tell us immediately if you see activity you do not recognise
  • Treat any email asking you to move money urgently as suspicious — we will never ask you to do that by email

Reporting a vulnerability

If you believe you have found a security issue, contact us and mark it for the attention of Security. We will acknowledge within two working days. Please do not test against live client accounts.

Any questions?

Speak to someone who can actually answer them.

Contact us Apply
Need a hand?Talk to us — we will reply as soon as possible.