05 / Enterprise Trust & Infrastructure Verified Standards ↗

Security by design.Not an afterthought.

Security is not a marketing badge or a feature bolted on after a product works. Across T2 Automations, our architecture follows two clear principles: client-side public utilities run locally in your browser with zero server data transmission, while all backend services, database-backed applications, and paid flagships (such as Every Pound and AppealMate) are engineered against our rigorous 13-layer defense standard.

Data in Transit

TLS 1.3 Strictly

HSTS enforced with modern cipher suites on all networked APIs and webhooks.

Data at Rest

AES-GCM-256

Zero-knowledge client-side encryption for synchronized vaults & sensitive records.

Data Residency

UK & EU Edge

Stored and processed exclusively under UK GDPR and Data Protection Act 2018.

Error Boundaries

Zero Leak Policy

Internal diagnostics stay in private logs; public errors remain fully sanitized.

The 13-Layer Production Audit Framework

Applied systematically to all backend services, account databases, and authenticated APIs before production release.

LAYER 01

Authentication & Verification

Passwordless WebAuthn/FIDO2 passkeys, secure one-time tokens with SHA-256 hashing, and constant-time HMAC validation. No weak default fallback secrets.

LAYER 02

Database & Tenant Isolation

Strict user-scoped queries and Row-Level Security (RLS). Every query binds to the authenticated session ID at the database engine level, preventing cross-tenant leakage.

LAYER 03

Zero-Knowledge Architecture

Sensitive user records (budgets, debts, private documents) are encrypted on the user's device prior to synchronization. We store encrypted envelopes; we do not hold your keys.

LAYER 04

Edge Defense & WAF

Global edge routing with DDoS mitigation, automated bot mitigation, TLS 1.3 termination, and geographic rate limits powered by Cloudflare's secure edge.

LAYER 05

Hardened Headers & CSP

Rigorous HTTP security headers deployed on all endpoints: Content-Security-Policy (CSP), frame-ancestors 'none' (anti-clickjacking), and strict Referrer policies.

LAYER 06

Error Boundary Sanitization

Complete separation between public user error states and server logs. Public requests receive clean, actionable notices; stack traces and DB credentials never leak to users.

LAYER 07

Automated TDD & Regression Gates

Automated test suites (unit tests, integration checks, and Playwright end-to-end flows) run before any code release to verify core security invariants and negative test cases.

LAYER 08

Vulnerability & Code Audits

Routine static analysis, third-party dependency vulnerability scanning, and pre-deployment code reviews across all API endpoints, webhooks, and payment callbacks.

LAYER 09

Real-Time Health & Monitoring

Independent synthetic health checks, edge worker telemetry, and automated alerting on abnormal status code spikes or API latency degradation.

LAYER 10

Data Sovereignty & Compliance

Strict compliance with UK GDPR and DPA 2018. User data is never sold, shared with ad brokers, or fed into AI model training pipelines.

LAYER 11

Disaster Recovery & Backups

Encrypted off-site snapshots and point-in-time recovery capabilities to safeguard business continuity against hardware or regional cloud failures.

LAYER 12

Payment & PCI Isolation

Payment card data never touches our servers. Card transactions are processed directly via Stripe Elements / Checkout with server-side signed session verification.

LAYER 13

Incident Response & Reporting

A structured incident response workflow with containment playbooks and transparent communication channels in the event of an operational anomaly.

Responsible Disclosure

We welcome reports from security researchers and the developer community.

Vulnerability Reporting Program

If you discover a security vulnerability or potential privacy weakness in any T2 Automations application, API route, or infrastructure service, please notify our security team directly. We commit to acknowledging your report within 24 hours and keeping you informed as we investigate and deploy remediation.

Security Desk: t2automations.desk@gmail.com or via our Studio Contact Desk (Subject: Security Disclosure)

Please do not attempt to access or modify data belonging to other users, degrade service availability, or perform volumetric attacks.