Skip to content

Legal centre

Security & Trust

How we protect the information entrusted to us, described accurately and without unverified claims.

Last reviewed: 2026-09-15

Our commitment

We maintain administrative, technical and organisational safeguards appropriate to the nature and volume of the information we process. We do not claim that information is “100% secure”, and we hold no security certification. Where an independent examination is completed in future, the report — not a badge — will be made available to clients on request.

Technical measures in place

  • HTTPS across the whole website, with HTTP Strict Transport Security.
  • A Content Security Policy, frame-ancestors protection, MIME-type sniffing protection, a strict referrer policy and a restrictive permissions policy.
  • Server-side validation and sanitisation of every submitted field, with a honeypot and rate limiting against automated abuse.
  • Row-level database security: website submissions cannot be read by the public and are restricted to authorised administrators.
  • No secrets, API keys or privileged database keys in browser code; all credentials are held as server-side environment variables.
  • No personal information in URLs, and redaction of personal data from application logs and error reports.
  • Administrator access is restricted, individually attributed and reviewed.

Service providers

We rely on established providers for hosting, database and email delivery, and we assess their security documentation before use.

  • Lovable / Cloudflare — Website hosting, edge delivery and server-side rendering
  • Supabase (managed PostgreSQL) — Database storage of inquiry and meeting-request records, and administrator authentication
  • Google Calendar — Scheduling of requested meetings, where a meeting is requested
  • Transactional email provider — Delivery of internal notification and confirmation emails (being confirmed)

Reporting a vulnerability

If you believe you have found a security issue, write to info@mulleradvisorygroup.com with enough detail to reproduce it. Please do not access, modify or delete data belonging to others, and give us a reasonable opportunity to remediate before public disclosure. We do not pursue researchers who act in good faith under these terms.

Incidents

We maintain an internal incident-response procedure covering detection, containment, assessment, notification and review. Where a personal-data breach is likely to require notification, we notify the competent authority and affected individuals within the time limits set by the law that applies.