Security
Last updated: June 2026
Our approach
Security is built into every CloverStacks project from day one. We follow current industry best practice for web and app development, including secure authentication, encrypted data in transit (HTTPS/TLS) and at rest, and least-privilege access.
Data protection
Personal data is handled in line with our Privacy Policy and UK GDPR. We minimise collection, restrict access to what is strictly necessary, and never sell client or end-user data.
Infrastructure
Production hosting runs on reputable cloud providers with regular security patching, automated backups and uptime monitoring. Credentials are stored in encrypted secret managers — never in source code.
Client ownership
When a project is delivered, you receive full ownership of the source code and data. You may host it independently at any time. CloverStacks retains no covert access to delivered systems.
Reporting a vulnerability
If you believe you've found a security issue in any CloverStacks-built site or app, please email wlkeely@gmail.com with details and steps to reproduce. We aim to acknowledge within 2 working days and to address verified issues promptly. Please do not publicly disclose until we've had a reasonable chance to fix it.