Trust
Security and data
Last revised 4 October 2026
Clients place their customers' data, their code and their accounts in our hands. This page sets out how we care for all three, both in your projects and in our own systems.
Before work begins
- An NDA comes first. Before you share anything sensitive, we sign your NDA or send you ours.
- Data processing agreement. Our contracts are under English law, and whenever we handle personal data for you they include a data processing agreement under UK GDPR.
- Your accounts, in your name. Code repositories, hosting, domains and app store accounts are opened in your name. We work through access that you grant and can withdraw at any time.
Where your data is hosted
For your project, the hosting region is agreed with you before launch, for example the UK or EU for data covered by GDPR. We use established cloud providers, and the accounts are in your name.
Our own client portal keeps its records and files in a database in London, United Kingdom. Files sit in private storage and are shared only through short-lived links once you have signed in.
Who has access to what
- Minimum access. Access to your project goes only to the people working on it, and only for the systems they need.
- Kept apart by design. In our client portal, database rules ensure that each client can read only their own projects, invoices, files and messages.
- A log of changes. Actions taken by staff in the portal, such as creating accounts or resetting passwords, are recorded in an activity log.
- Encrypted in transit. Our website and portal are served over HTTPS only, and browsers are instructed never to fall back to an unencrypted connection.
How we build securely
- As we build, we check permissions and input validation, and we keep libraries up to date.
- Secrets such as API keys are held in the hosting provider's encrypted settings and never in the code.
- Forms are guarded against spam and automated abuse.
- With a care plan, security patches and dependency updates are applied every month and backups are taken daily, with response times set out in writing.
Reporting a security issue
If you believe you have found a vulnerability in arbcodes.com or in a system we look after, email ask@arbcodes.com with “Security” in the subject line. Please allow us a reasonable time to fix it before you tell anyone else, and do not access or change data that is not yours. We will reply to confirm that we are looking into it.
Our privacy notice explains how we handle personal information.
