Trust

Security

How we protect the logins, keys and data you trust us with, and how to tell us if something is wrong.

Secrets sealed at rest

Test logins, AI keys and gateway credentials are encrypted before they reach the database, with a key the database never holds.

AES-256-GCM

Only sites you have proved are yours

Journeys, and the test logins they type, only run on a domain you have verified by DNS record, a file, or the WordPress plugin.

ownership before access

A browser that cannot wander

Every check opens a fresh browser session, and every request it makes, redirects included, is refused if it points at a private network.

private address guard

Passwords nobody can read

Passwords are stored as one-way hashes. Sign in is rate limited and protected by reCAPTCHA, and the session cookie is out of reach of scripts.

bcrypt, HttpOnly cookie

Card details never touch us

Cards are entered on Stripe's or UBL's own payment pages. We receive the result, check it with the gateway, and keep no card numbers.

gateway-hosted checkout

A strict page policy

Every page is served with a Content-Security-Policy that blocks inline scripts, and public status pages carry no scripts at all.

Content-Security-Policy