AZURY DIGITAL
Our products Services Websites In the workshop Free tools Why us Contact Get in touch Client portal
Security & Trust

Keeping your data safe

Last reviewed: 12 July 2026

Your business data — and your own customers' or tenants' information — is exactly the kind of data that has to be looked after properly. This page explains, in plain terms, the measures we take to protect it. We follow a defence-in-depth approach: several independent layers of protection, so no single failure exposes your data.

At a glance

  • ✓ Hosted in the UK on ISO 27001-certified infrastructure
  • ✓ Encrypted in transit (HTTPS/TLS) and encrypted, off-site backups (AES-256)
  • ✓ Each customer's data is fully separated — you only ever see your own
  • ✓ Key-only administrator access; passwords are never stored in plain text
  • ✓ Firewalled, automatically patched servers with active intrusion prevention
  • ✓ Application code security-reviewed and hardened against common attacks
  • ✓ Automated backups every hour, held off-site and encryption-protected

1. Where your data is stored

Your data is hosted in the United Kingdom by Fasthosts, whose data centres are certified to ISO/IEC 27001 — the international standard for information-security management. Keeping data in the UK also means it stays within UK data-protection law.

2. Encryption

In transit: every connection to our apps is protected with HTTPS/TLS encryption, so information moving between your device and our servers can't be read along the way. If anyone tries to reach the app over an unencrypted (http) address, they're immediately redirected to the secure (https) version, and their browser is told to use the secure connection every time after that — so data is never sent unprotected.

At rest: our backups are encrypted with AES-256 (the same class of encryption used by banks and governments), and the key that unlocks them is held only by us — a backup copy on its own is useless to anyone else.

3. Your data is kept separate

Our apps are built so that each customer's information is isolated. Every record is tied to the account that owns it, and the system only ever returns your own data to you. One customer can never see, or reach, another customer's information — and that separation is preserved in our backups too.

4. Secure access and sign-in

  • Administrator access is by cryptographic key only. Password logins to the server are switched off entirely, and remote "root" (full-control) access is disabled.
  • Passwords are never stored in readable form. Account passwords are protected using bcrypt one-way hashing, so even we can't see them.
  • Secure single sign-on. When you open an app from your account, it uses short-lived, single-use, app-specific sign-in tokens — a link can't be reused or replayed.
  • Instant sign-out everywhere. Changing your password immediately ends any other active sessions.
  • Brute-force protection. Repeated failed sign-in attempts are rate-limited and blocked.

5. A hardened, monitored server

  • Firewalled by default. The server refuses all incoming connections except the few that are genuinely needed (secure web traffic and protected admin access).
  • Databases are not exposed to the internet. They can only be reached by the application itself, never directly from outside.
  • Automatic security updates. The server keeps itself patched against newly discovered vulnerabilities.
  • Active intrusion prevention. Repeated malicious attempts are detected and the offending source is automatically blocked.

6. Backups and disaster recovery

Your data is backed up automatically every hour, with a full daily server image, using Acronis Cyber Protect. Backups are encrypted, stored off-site from the live server, and retained so we can recover from an earlier point if ever needed. Database backups are taken cleanly and consistently, so a restore brings everything back intact.

7. Secure development and change control

Our application code has been through an in-depth security review, including adversarial (red-team-style) verification, and is hardened against common web-application attacks. Every change to the live system is reviewed and logged before it goes out, so nothing reaches your data unchecked.

8. Payments

Card payments are handled by Stripe, a global PCI-DSS-certified payment provider. We never see or store your full card details.

9. Data protection and your rights

We handle personal data in line with the UK GDPR and the Data Protection Act 2018, and we're registered with the Information Commissioner's Office (ICO) under reference ZC188926. When you use our apps to store information about your own clients or tenants, you remain in control of that data and we act as your data processor. Full details are in our Privacy Policy.

10. Our ongoing commitment

Security isn't a one-off task — it's something we maintain. We review our protections regularly and strengthen them as new threats emerge and best practice moves on. Your data is protected by multiple independent safeguards working together, and we treat it with the same care we'd expect for our own.

If you have any questions about security or data protection, email us at info@azurydigital.co.uk.

AZURY DIGITAL

Tech that does the hard part — software, websites & custom PC builds for UK business.

Products

Lettright Lettright modules Lushera MyWorkBase Tiny Treasurer

Company

Services Websites In the workshop Free tools Why us Testing Portal Contact

Legal

Privacy Policy Terms & Conditions Security info@azurydigital.co.uk

Azury Digital & Tech Solutions Ltd is registered in England and Wales, company no. 13446812. Registered office: 23a The Precinct, London Road, Waterlooville PO7 7DT. ICO registration ZC188926.
© 2026 Azury Digital & Tech Solutions Ltd. All rights reserved.

ICO RegisteredRef ZC188926
UK GDPR compliantData handled lawfully
ISO 27001 datacentresUK-hosted infrastructure
No tracking cookiesNo ads or analytics