Legal centre
Security & Trust
How we protect the information entrusted to us, described accurately and without unverified claims.
Last reviewed: 2026-09-15
Our commitment
We maintain administrative, technical and organisational safeguards appropriate to the nature and volume of the information we process. We do not claim that information is “100% secure”, and we hold no security certification. Where an independent examination is completed in future, the report — not a badge — will be made available to clients on request.
Technical measures in place
- HTTPS across the whole website, with HTTP Strict Transport Security.
- A Content Security Policy, frame-ancestors protection, MIME-type sniffing protection, a strict referrer policy and a restrictive permissions policy.
- Server-side validation and sanitisation of every submitted field, with a honeypot and rate limiting against automated abuse.
- Row-level database security: website submissions cannot be read by the public and are restricted to authorised administrators.
- No secrets, API keys or privileged database keys in browser code; all credentials are held as server-side environment variables.
- No personal information in URLs, and redaction of personal data from application logs and error reports.
- Administrator access is restricted, individually attributed and reviewed.
Service providers
We rely on established providers for hosting, database and email delivery, and we assess their security documentation before use.
- Lovable / Cloudflare — Website hosting, edge delivery and server-side rendering
- Supabase (managed PostgreSQL) — Database storage of inquiry and meeting-request records, and administrator authentication
- Google Calendar — Scheduling of requested meetings, where a meeting is requested
- Transactional email provider — Delivery of internal notification and confirmation emails (being confirmed)
Reporting a vulnerability
If you believe you have found a security issue, write to info@mulleradvisorygroup.com with enough detail to reproduce it. Please do not access, modify or delete data belonging to others, and give us a reasonable opportunity to remediate before public disclosure. We do not pursue researchers who act in good faith under these terms.
Incidents
We maintain an internal incident-response procedure covering detection, containment, assessment, notification and review. Where a personal-data breach is likely to require notification, we notify the competent authority and affected individuals within the time limits set by the law that applies.
