Trust Center
Security, compliance, and transparency at WEBCEO.
Security
We follow industry-standard security practices across hosting, development, and data handling. All web properties we operate ship with security headers and HTTPS.
Encryption
We encrypt data in transit with TLS and encourage PGP for sensitive security correspondence.
Compliance
We are GDPR-aligned. See our privacy policy for how we collect, use, and protect personal data.
Security Disclosure Policy
If you discover a security vulnerability in any WEBCEO product or website, please report it privately to security@webceo.co.uk. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to investigate and remediate.
- Provide a clear description and reproducible steps.
- Include the affected URL and version if applicable.
- Do not access, modify, or exfiltrate other users' data.
- Do not perform disruptive tests (e.g. DoS) or social engineering.
We will acknowledge your report within 5 business days and keep you informed as we work towards a fix.
PGP Encryption Key
For sensitive correspondence, you may encrypt messages using our PGP key. To obtain the key, email security@webceo.co.uk with the subject “PGP Key Request”.
Acknowledgements
We are grateful to independent security researchers who help us keep our systems safe. We publish validated reports here with the reporter's consent.