Security by design.Not an afterthought.
Security is not a marketing badge or a feature bolted on after a product works. Across T2 Automations, our architecture follows two clear principles: client-side public utilities run locally in your browser with zero server data transmission, while all backend services, database-backed applications, and paid flagships (such as Every Pound and AppealMate) are engineered against our rigorous 13-layer defense standard.
Data in Transit
HSTS enforced with modern cipher suites on all networked APIs and webhooks.
Data at Rest
Zero-knowledge client-side encryption for synchronized vaults & sensitive records.
Data Residency
Stored and processed exclusively under UK GDPR and Data Protection Act 2018.
Error Boundaries
Internal diagnostics stay in private logs; public errors remain fully sanitized.
The 13-Layer Production Audit Framework
Applied systematically to all backend services, account databases, and authenticated APIs before production release.
Authentication & Verification
Passwordless WebAuthn/FIDO2 passkeys, secure one-time tokens with SHA-256 hashing, and constant-time HMAC validation. No weak default fallback secrets.
Database & Tenant Isolation
Strict user-scoped queries and Row-Level Security (RLS). Every query binds to the authenticated session ID at the database engine level, preventing cross-tenant leakage.
Zero-Knowledge Architecture
Sensitive user records (budgets, debts, private documents) are encrypted on the user's device prior to synchronization. We store encrypted envelopes; we do not hold your keys.
Edge Defense & WAF
Global edge routing with DDoS mitigation, automated bot mitigation, TLS 1.3 termination, and geographic rate limits powered by Cloudflare's secure edge.
Hardened Headers & CSP
Rigorous HTTP security headers deployed on all endpoints: Content-Security-Policy (CSP), frame-ancestors 'none' (anti-clickjacking), and strict Referrer policies.
Error Boundary Sanitization
Complete separation between public user error states and server logs. Public requests receive clean, actionable notices; stack traces and DB credentials never leak to users.
Automated TDD & Regression Gates
Automated test suites (unit tests, integration checks, and Playwright end-to-end flows) run before any code release to verify core security invariants and negative test cases.
Vulnerability & Code Audits
Routine static analysis, third-party dependency vulnerability scanning, and pre-deployment code reviews across all API endpoints, webhooks, and payment callbacks.
Real-Time Health & Monitoring
Independent synthetic health checks, edge worker telemetry, and automated alerting on abnormal status code spikes or API latency degradation.
Data Sovereignty & Compliance
Strict compliance with UK GDPR and DPA 2018. User data is never sold, shared with ad brokers, or fed into AI model training pipelines.
Disaster Recovery & Backups
Encrypted off-site snapshots and point-in-time recovery capabilities to safeguard business continuity against hardware or regional cloud failures.
Payment & PCI Isolation
Payment card data never touches our servers. Card transactions are processed directly via Stripe Elements / Checkout with server-side signed session verification.
Incident Response & Reporting
A structured incident response workflow with containment playbooks and transparent communication channels in the event of an operational anomaly.
Responsible Disclosure
We welcome reports from security researchers and the developer community.
Vulnerability Reporting Program
If you discover a security vulnerability or potential privacy weakness in any T2 Automations application, API route, or infrastructure service, please notify our security team directly. We commit to acknowledging your report within 24 hours and keeping you informed as we investigate and deploy remediation.
Please do not attempt to access or modify data belonging to other users, degrade service availability, or perform volumetric attacks.