Security Information
Operator details must be completed before launch.
Replace every highlighted placeholder such as
Replace every highlighted placeholder such as
[LEGAL ENTITY], [REGISTERED ADDRESS], [HOSTING COUNTRY], and [RETENTION PERIOD] so the documents accurately describe the live service.Current safeguards to confirm
- HTTPS/TLS for app and API traffic.
- Passwords hashed with Argon2id or bcrypt; never stored in plain text.
- Least-privilege database and administrative access.
- Secure, HttpOnly, SameSite session cookies where cookies are used.
- Rate limiting, input validation and protection against common web attacks.
- Encrypted backups, tested restoration and documented retention.
- Logging and incident response without unnecessary personal data.
- Regular dependency, server and access reviews.
Report a vulnerability
Email security@gesd.co.uk. Provide steps to reproduce and avoid accessing or changing other users’ data. We request coordinated disclosure.
Security limitations
No service is completely secure. Users should use unique credentials, protect devices and remove calendar access that is no longer needed.