Security
Security
How we protect the software we build and the data inside it.
Our approach
Our products hold sensitive information, such as candidate records, case notes and training histories. We treat security as part of building software, not a separate step at the end.
Protecting data
- Data is encrypted in transit and at rest.
- Systems are hosted with established cloud providers. We tell customers where their data is hosted before they sign up.
- Backups run regularly, and we test that they can be restored.
- Every customer gets a data processing agreement. When you use our products, we process your data on your behalf and only as you instruct.
Access
- Staff only have access to the systems and data their work needs.
- Multi-factor authentication is required on all our internal systems.
- Access is reviewed regularly and removed promptly when it is no longer needed.
- We only access customer data to provide support, and with the customer's permission.
How we develop
- Every change is reviewed by another developer before release.
- Automated tests run on every change.
- Third-party dependencies are monitored for known vulnerabilities and updated promptly.
- Development, testing and live systems are kept separate.
Reporting a vulnerability
If you think you have found a security problem in our website or products, email hello@trunkfield.co.uk. We will acknowledge it within two working days and keep you updated while we fix it.
Please give us reasonable time to fix the problem before telling anyone else, and don't access or change other people's data while testing. Our contact details are also published in security.txt.
Security documents
Customers and prospective customers can ask for our current security documentation and data processing agreement.