Security
What we do to keep customer pages and accounts secure — and what we ask of you.
We only describe measures that are actually in place. If you need detail on anything below for your own records, ask and we will confirm it in writing.
1. Page security
Pages we build are served over HTTPS. Software, themes and plugins are kept up to date on pages covered by a maintenance agreement. Pages without maintenance are the customer's responsibility to keep updated. Pages are backed up so they can be restored if something goes wrong.
2. Customer account security
Before making changes to a page we verify that the request comes from an authorised contact. We won't act on instructions we can't reasonably verify, and we may ask you to confirm a request from the email address we hold on file.
3. Passwords
We use unique passwords for the systems we operate, and two-factor authentication where the provider supports it. We ask customers to do the same, and never to send passwords by text message or social media. If we need to send you a credential, we'll agree a sensible way to do it.
4. Payment security
Payments are processed by third-party payment providers. We do not see or store full card details. We'll never email you asking you to pay into different bank details — if you receive such a message, email us at contact@flvr.uk to check before paying anything.
5. Access controls
Access to customer systems is limited to what's needed to do the work, and removed when it's no longer needed. Because this is a one-person business, access is held by the owner only.
6. Monitoring
We check that customer pages are reachable and act on any problem a provider or customer reports. Where we're notified of a problem by a provider or a customer, we investigate promptly.
7. Incident response
- Contain the problem — for example taking a site offline or resetting credentials.
- Assess what happened and what was affected.
- Tell affected customers what we know and what we're doing.
- Where personal data is involved, consider whether the ICO and affected people must be notified, and do so within the required timeframes.
- Fix the cause and record what we changed.
8. Responsible disclosure
If you've found a security problem with this website or a site we manage, please email contact@flvr.uk with enough detail to reproduce it. Please don't access or change other people's data, and give us a reasonable chance to fix it before publishing. We'll acknowledge your report and keep you updated. We don't currently offer payment for reports.