Back to Trust Centre

Security

Security Overview

A public, plain-English summary of verified and intended security controls without operational detail.

Version

0.1

Updated

23 June 2026

Owner

Security owner

Our security approach

Affordit applies proportionate controls across identity, access, code, infrastructure, suppliers, monitoring, backups and incident handling. Controls are reviewed against the live system rather than treated as true simply because they appear in a policy.

This public overview describes the approach without exposing information that could weaken the service or reveal another user’s data.

Protecting access

Affordit uses account authentication, ownership-scoped data access and row-level database protections to limit access to signed-in user records. Privileged access is restricted and is intended to use multi-factor authentication.

Access should be role-based, approved by an owner and removed when it is no longer needed. Shared privileged accounts are prohibited unless technically unavoidable and subject to formal controls.

Protecting information

Affordit requires encrypted communication in transit and appropriate encryption at rest from relevant providers. Secrets and credentials must be kept out of source code, client bundles and public logs.

Logs should support security and reliability without recording passwords, access tokens, full financial inputs or unnecessary personal information.

Protecting the service

Controls include encrypted service communication, secure secret management, version-controlled changes, review, automated testing, dependency management, monitoring, backups and incident handling.

Security-sensitive changes require additional review. Test data should be synthetic or minimised, and dependencies should be assessed and remediated according to severity and risk.

Suppliers and resilience

Material suppliers are reviewed for security, privacy, resilience, data location, deletion, subprocessors and exit risk. Supplier access and data handling should be limited to the service purpose.

Business continuity and recovery arrangements cover critical dependencies. Detailed recovery targets, backup locations and emergency credentials are restricted rather than published.

Incident response

Suspected incidents are identified, contained, assessed, remediated and reviewed. Where personal information is involved, notifications are made to affected organisations, people or regulators where required.

Users should report suspected account compromise or a security concern through the monitored support route without sending passwords, access tokens or exploit details through an insecure channel.

What is not published

Detailed architecture, incident procedures, vulnerability findings, penetration-test reports, backup locations and security operating instructions are not published openly. They may be shared selectively under appropriate due-diligence controls.

No unsupported certifications

Affordit does not claim Cyber Essentials, penetration-test assurance, formal WCAG certification or another external accreditation unless it has genuinely been completed and approved for publication.

Ongoing review

Security controls, incidents, vulnerabilities and material suppliers are reviewed regularly and when the product, architecture or risk changes. Critical corrections may follow an emergency approval and retrospective review process.

Questions or concerns

Contact the monitored Affordit support route. Include the affected page, but do not send passwords, card details, bank details, identity documents or unnecessary financial information.

Report a security concern

Updated: 23 June 2026

Version: 0.1

Classification: Public