Our security approach
Affordit applies proportionate controls across identity, access, code, infrastructure, suppliers, monitoring, backups and incident handling. Controls are reviewed against the live system rather than treated as true simply because they appear in a policy.
This public overview describes the approach without exposing information that could weaken the service or reveal another user’s data.
Protecting access
Affordit uses account authentication, ownership-scoped data access and row-level database protections to limit access to signed-in user records. Privileged access is restricted and is intended to use multi-factor authentication.
Access should be role-based, approved by an owner and removed when it is no longer needed. Shared privileged accounts are prohibited unless technically unavoidable and subject to formal controls.
Protecting information
Affordit requires encrypted communication in transit and appropriate encryption at rest from relevant providers. Secrets and credentials must be kept out of source code, client bundles and public logs.
Logs should support security and reliability without recording passwords, access tokens, full financial inputs or unnecessary personal information.
Protecting the service
Controls include encrypted service communication, secure secret management, version-controlled changes, review, automated testing, dependency management, monitoring, backups and incident handling.
Security-sensitive changes require additional review. Test data should be synthetic or minimised, and dependencies should be assessed and remediated according to severity and risk.
Suppliers and resilience
Material suppliers are reviewed for security, privacy, resilience, data location, deletion, subprocessors and exit risk. Supplier access and data handling should be limited to the service purpose.
Business continuity and recovery arrangements cover critical dependencies. Detailed recovery targets, backup locations and emergency credentials are restricted rather than published.
Incident response
Suspected incidents are identified, contained, assessed, remediated and reviewed. Where personal information is involved, notifications are made to affected organisations, people or regulators where required.
Users should report suspected account compromise or a security concern through the monitored support route without sending passwords, access tokens or exploit details through an insecure channel.
What is not published
Detailed architecture, incident procedures, vulnerability findings, penetration-test reports, backup locations and security operating instructions are not published openly. They may be shared selectively under appropriate due-diligence controls.
No unsupported certifications
Affordit does not claim Cyber Essentials, penetration-test assurance, formal WCAG certification or another external accreditation unless it has genuinely been completed and approved for publication.
Ongoing review
Security controls, incidents, vulnerabilities and material suppliers are reviewed regularly and when the product, architecture or risk changes. Critical corrections may follow an emergency approval and retrospective review process.
Questions or concerns
Contact the monitored Affordit support route. Include the affected page, but do not send passwords, card details, bank details, identity documents or unnecessary financial information.
Report a security concern