Skip to content
WEBCEO Logo

Trust Center

Security, compliance, and transparency at WEBCEO.

Security

We follow industry-standard security practices across hosting, development, and data handling. All web properties we operate ship with security headers and HTTPS.

Encryption

We encrypt data in transit with TLS and encourage PGP for sensitive security correspondence.

Compliance

We are GDPR-aligned. See our privacy policy for how we collect, use, and protect personal data.

Security Disclosure Policy

If you discover a security vulnerability in any WEBCEO product or website, please report it privately to security@webceo.co.uk. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.

  • Provide a clear description and reproducible steps.
  • Include the affected URL and version if applicable.
  • Do not access, modify, or exfiltrate other users' data.
  • Do not perform disruptive tests (e.g. DoS) or social engineering.

We will acknowledge your report within 5 business days and keep you informed as we work towards a fix.

PGP Encryption Key

For sensitive correspondence, you may encrypt messages using our PGP key. To obtain the key, email security@webceo.co.uk with the subject “PGP Key Request”.

Acknowledgements

We are grateful to independent security researchers who help us keep our systems safe. We publish validated reports here with the reporter's consent.