Website security
We use proportionate technical and organisational safeguards to protect this website and the information sent through it.
Secure connection
The public website is intended to be served only over HTTPS. Security headers restrict framing, mixed content, unnecessary browser permissions and unapproved destinations for scripts and forms.
Protected enquiries
Enquiries are validated on the server, limited in size, checked for automated submissions and sent to an allowlisted Google endpoint using a server-only secret. Do not send confidential, special-category or unnecessary personal information.
Responsible reporting
If you believe you have found a security problem, use our contact page or write to the registered office marked “Security report”. Do not access, change, retain or share anybody else’s information. We will acknowledge genuine reports and investigate them proportionately.
No absolute guarantee
No website can truthfully promise to be unhackable. We review dependencies and controls, restrict access and respond to credible reports, but this page is not an independent security certification or penetration-test report.
