Data Security & Protection

This page describes the technical and organisational measures that protect data in the Legionella Logbook platform and mobile app. It is kept in step with our Privacy Policy and Terms and Conditions.

Infrastructure & Data Location

Customer data is stored and processed in the United Kingdom. Our database, file storage, backups and application servers run in London on infrastructure provided by Supabase (on Amazon Web Services) and Vercel, in data centres certified to ISO 27001 and SOC 2 Type II. Supporting services that do not hold the logbook itself run in the European Union and the United States under the transfer safeguards described in our Privacy Policy: error and crash monitoring and email delivery in the EU, and background job scheduling in the US. The platform is a managed, serverless deployment. There are no servers for us to patch by hand: the operating systems, database engine and runtimes are maintained and patched by the providers.

Encryption

All data is encrypted in transit and at rest, including backups. • In transit: every connection to the platform, the mobile app's API and our file storage uses HTTPS with TLS 1.2 or higher. Plain HTTP is not served, and browsers are instructed to use HTTPS only on the platform (HSTS with a two-year policy). • At rest: database volumes, file storage and backups are encrypted with AES-256 by our infrastructure providers. • On mobile devices: the App's session tokens are encrypted with AES, and the key is held in the device's secure keychain (iOS) or keystore (Android).

Application Security

• Platform-level DDoS mitigation and firewall provided by our hosting provider. • All database access uses parameterised queries. User input is never concatenated into SQL. • Every request is validated against a strict schema before it is processed, with size limits on every field and file. • Security headers on the platform prevent framing by other sites, MIME-type sniffing and referrer leakage. • Third-party dependencies and platform versions are kept current.

Authentication

• Accounts are created by invitation from an organisation administrator only. There is no public sign-up. Invitation links are single-use, expire after seven days and are stored only as a hash. • Passwords must be between 8 and 72 characters, in line with NIST SP 800-63B guidance, and are stored hashed by Supabase Auth. We never see or store them in plain text. • Users can turn on multi-factor authentication for their account with an authenticator app, so a stolen password alone is not enough to sign in. • Changing a password signs out every other session for that account. Changing a login email requires confirmation from both the old and the new address. • Users receive a security notification email whenever their password is changed. • Sessions use short-lived tokens that are refreshed automatically, and access ends as soon as an administrator removes the user from the organisation.

Authorisation & Access Control

• Five roles (auditor, technician, manager, admin and owner) in a strict hierarchy, with site-level scoping so a user can be limited to specific sites within their organisation. • Every API request is authorised on the server before any data is read or written. The browser and the mobile app never talk to the database directly. • Row-level security is enabled on every table and denies all direct access by default, so even a coding mistake in the client cannot read another organisation's data. • Our own staff access customer data only through named accounts and only for support and operations.

Files & Documents

• Photos, certificates and documents are stored in private buckets that are not publicly accessible. • Every upload and download goes through a time-limited signed URL issued by the platform after the request has been authorised: one hour by default and never more than 24 hours. • File types and sizes are restricted per bucket, and files are removed from storage when their record is deleted.

Mobile App Security

The mobile app is a field companion for technicians and is designed to work offline. • Sign-in uses the same invite-only accounts as the platform. Session tokens are encrypted at rest with the key held in the device keychain (iOS) or keystore (Android). • Downloaded site data is removed from the device on sign-out, and a user whose access is revoked can no longer sync or download. • On Android, the App's data is excluded from automatic device backups. • The App requests only the permissions it needs: camera and photo library, used solely to attach evidence photos. It does not use location, contacts or the microphone. • Crash reports contain no IP address, name, email address or user identifier. • The App enforces a minimum version and will not connect to the platform until it is updated, so security fixes reach every device.

Data Segregation

The platform is multi-tenant. Each organisation's data is logically segregated, enforced at two layers: every server request is checked against the caller's organisation membership and role before any data is returned, and row-level security in the database denies all direct access by default. No organisation can see another organisation's sites, people or records, and we never use customer data for our own commercial purposes.

Backup & Disaster Recovery

• The database is backed up automatically every day, and backups are retained for 7 days, encrypted, in the United Kingdom. • Our recovery objectives are a Recovery Time Objective of 24 hours and a Recovery Point Objective of 24 hours. • The application layer runs across multiple availability zones with automatic failover, and availability is monitored around the clock. • Customers can export their compliance records at any time and are encouraged to keep their own copies, as UK health and safety guidance expects.

Monitoring & Logging

• Every record is attributed to the user who created or last changed it, with a timestamp. This attribution is part of the organisation's compliance record. • Authentication events, including sign-ins, password and email changes and invitations, are logged. • Errors and availability are monitored automatically, with alerting to our engineering team. Error reports are scrubbed of secrets and tokens before they leave the application and never contain customer credentials.

Secure Development & Operations

• Staging and production are separate, isolated environments with their own databases, credentials and access. • Development and test environments use synthetic data only. Production data is not copied into them. • Secrets and API keys are held in the hosting providers' encrypted environment configuration, never in source code. • Changes are version-controlled and are type-checked and built automatically before deployment.

Incident Management

• Security incidents are triaged and contained by our engineering team, with a defined escalation path to the company's director. • If a personal data breach is likely to result in a risk to individuals, we notify affected customers without undue delay and the Information Commissioner's Office within 72 hours where required. • Every incident is followed by a post-incident review, and the resulting fixes are tracked to completion.

Data Minimisation

• We collect only the professional details needed to run the service: name, work email and role for users; name, contact details, job title and training records for personnel; and the compliance records themselves. • Photos and documents are uploaded only when a user chooses to attach them to a record. • The platform does not use advertising or tracking technologies, and the mobile app contains no analytics SDK. • Retention periods and deletion on request are set out in our Privacy Policy.

Sub-Processors & Governance

• We use a small number of specialist providers to host and run the service. Their categories and locations are listed in our Privacy Policy. The full named list, with locations and safeguards, is included in our Data Processing Agreement, available on request. • Every sub-processor is bound by a written contract to act only on our instructions and to protect data to at least the standard we commit to here. • Customers are notified before a sub-processor is added or replaced and may object. • We are registered with the Information Commissioner's Office (registration ZB857401) and act as processor for the data organisations put into their logbook.

Security Standards

Our infrastructure providers maintain independent certifications, including SOC 2 Type II and ISO 27001, which are verified regularly by external auditors. Copies of provider attestations can be supplied on request to support customer due diligence. We build the platform against recognised guidance, including the OWASP Top 10 for application security and NIST SP 800-63B for authentication.

Security Enquiries & Responsible Disclosure

To ask a security question, request our Data Processing Agreement or provider attestations, or report a vulnerability, contact contact@legionellalogbook.com. If you report a vulnerability in good faith and follow the rules in our Terms and Conditions, we will not take legal action against you, and we will acknowledge your report within two business days. This security statement is reviewed alongside our Privacy Policy and Terms and Conditions, and customers are told of any significant change to our security practices. Last updated: 26 September 2026. Version: 1.2