• Home
  • Legal
  • Security

Security

This platform holds site layouts, staffing patterns, vulnerabilities and protective measures. That is exactly the information an attacker would want, and it is protected accordingly.

Last updated: 5 October 2026

In transit and at rest

  • HTTPS throughout. All traffic to the website and the platform is encrypted in transit, with HTTP redirected to HTTPS and HSTS enabled.
  • Encryption at rest for the database and uploaded files, where the hosting platform supports it.
  • Secure file storage — uploaded documents are served only through an authenticated, access-controlled route, never from a publicly guessable location.

Accounts and access

  • Password hashing using a modern algorithm. Passwords are never stored or logged in readable form, and we cannot tell you what yours is.
  • Role-based access — account users can be given full (edit) or view-only access, so people get the least access that lets them do their job.
  • Session management — secure, HTTP-only session cookies, session regeneration on sign-in, and idle timeout.
  • Multi-factor authentication — required for administrator accounts (time-based one-time codes).
  • Administrative access is restricted to named individuals, protected by additional controls, and logged.

Uploads

  • File type and size restrictions on everything uploaded.
  • Uploads are stored outside the executable web path, and the server is configured not to execute anything in the upload directory.
  • Malware scanning of uploaded files (ClamAV).

Monitoring and resilience

  • Audit logging of significant events, including administrative actions and access to customer records.
  • Logging and monitoring of the infrastructure, with alerting on anomalies.
  • Backups taken daily, retained for 30 days, and restore-tested quarterly.
  • Disaster recovery — in a disaster we restore from the most recent daily backup (a recovery point objective of up to 24 hours) and aim to restore service as quickly as practicable.

How we build

  • Parameterised database queries throughout, so user input is never concatenated into SQL.
  • Output encoding on every page, and cross-site request forgery protection on every form.
  • Security headers set at the server, including content type options, frame options and a referrer policy.
  • Dependencies kept current, with vulnerability alerts monitored.
  • Penetration testing — carried out before launch, with findings remediated.

Data protection

  • Data is stored in the United Kingdom (AWS London region).
  • Retention controls, so information is not kept indefinitely by default.
  • Processors engaged under written contracts meeting UK GDPR requirements.
  • See our Privacy Policy for the detail.

What we ask of you

  • Use a strong, unique password — a short phrase of three or four words is both stronger and easier than a mangled word.
  • Give each person their own account rather than sharing a login.
  • Remove users when they leave.
  • Think about who needs to see the whole record and who only needs part of it.
  • Do not email us the sensitive detail of your premises' vulnerabilities — ask us for a secure route.

Reporting a vulnerability

If you believe you have found a security problem, please tell us before telling anyone else. Email support@martynslawworkbook.co.uk with enough detail to reproduce it.

We will acknowledge your report within 5 working days, keep you updated, and will not pursue anyone who reports a genuine issue in good faith and does not access, modify or retain other people's data in the process.

Please do not run automated scanning or load testing against the service without asking us first.