Legal
Security
How we protect the software we build, the client data we handle, and how to report a security issue to us.
Last updated 23 September 2026
1. Security in the software we build
- Role-based access control enforced on the server, so a user only sees and changes what their role allows.
- Audit logging of changes to business records, showing who changed what and when.
- Encrypted connections (HTTPS/TLS) for every environment we deploy.
- Input validation and parameterised queries to protect against injection attacks.
- Hashed passwords and secure session handling, with multi-factor authentication available where the project needs it.
- A security and code-quality review before every production launch.
2. How we handle client data
- We sign a non-disclosure agreement before scoping, on request.
- Access to client systems and data is limited to the engineers working on the project and removed when the engagement ends.
- We use test data wherever possible and avoid copying production data to developer machines.
- Credentials are kept in a password manager or secrets store, never in source code.
3. Delivery and hosting
- Applications are deployed in containers, to the cloud or to your own servers, including in-country hosting where data residency rules require it.
- All code is kept in version control, and changes are reviewed before release.
- Backups and monitoring are configured as part of launch.
4. Ownership and continuity
When a project is complete and paid for, every repository, credential and piece of documentation is transferred to your organisation. You are never dependent on us to keep your system running.
5. Compliance
We design systems to help clients meet their obligations under India's Digital Personal Data Protection Act 2023, Saudi Arabia's Personal Data Protection Law and the GDPR, including consent capture, access controls and data export and deletion. We are happy to complete your vendor security questionnaire during scoping.
6. Reporting a vulnerability
If you believe you have found a security issue in this website or in a system we operate, email info@webfarmtech.com with “Security” in the subject line. Include enough detail for us to reproduce it.
We will acknowledge your report within three working days and keep you updated until it is fixed. Please give us reasonable time to fix the issue before disclosing it, and do not access or modify data that is not yours. See also our Privacy Policy.