Security & reliability
When we build an automation for you, your data passes through our infrastructure. Here's how we make sure it's safe in transit, safe at rest, and unavailable to anyone who shouldn't see it.
Our approach
We operate on three principles: minimise what we hold, control who can reach it, and fail loudly if something breaks. Each of the controls below sits under one of these.
The best way to keep sensitive data safe is to never ingest it in the first place. Personal notes, session content, and other non-essential fields are stripped at the boundary before the pipeline sees them. We call this privacy by elimination.
Every administrative surface sits behind Cloudflare Zero Trust with named-user access control and multi-factor authentication. No shared logins, no default passwords, no unguarded admin endpoints facing the public internet.
Every production workflow is wired to an error-handler pipeline. Failures become an email in our inbox within minutes — not a client complaint three weeks later. You hear about incidents from us first.
Technical controls
Honest status on every technical control. Live means it is in production today. In progress means we have a concrete plan and date.
Policy & compliance
We treat every client engagement as if the ICO will audit it tomorrow. These are the policy and contractual controls that sit alongside the technical ones.
Reliability
We don't claim four nines. What we do claim, we can back up.
Target: 99.5% uptime on scheduled workflows. That's roughly 3.6 hours of downtime per month as the worst case. We measure it on every production flow via the error-handler pipeline, and we report it honestly to every client on the monthly review.
When an incident does happen — platform outage, API change, credential expiry — the sequence is: detect via error handler, notify the client, fix, document, and include it in the next review. Nothing gets quietly swept under a rug.
Every client engagement comes with a short written runbook covering what can go wrong, how we'd spot it, and what we'd do about it. If we can't explain the failure modes, we haven't understood the system.
Questions?
We're happy to walk any prospective client through our DPA draft, our sub-processor list, or the specific controls protecting a pipeline we're building for you.
Get in touch