This Security Overview summarises how iSolicitude LTD, trading as “iSolicitude”, protects data. Certain operational specifics are intentionally omitted so as not to assist attackers.
- Encryption in transit (TLS) across all pages and portals, with HTTP Strict Transport Security (HSTS) enabled.
- Passwords stored using modern one-way hashing, with a minimum length of 12 characters and account lockout on repeated failures.
- Multi-factor authentication required for staff and privileged accounts, with step-up verification for sensitive actions.
- Role-based access control and portal isolation between clients, affiliates and staff.
- Anti-forgery protection, security response headers, rate limiting and bot protection on public forms.
- Uploaded files validated by type and size and stored outside the public web root.
- Payment card data handled by PayPal; we never store card numbers or security codes.
- Audit logging of security-relevant events, with IP addresses hashed for analytics.
- A documented incident-response procedure, including regulatory and data-subject notification steps.
Please report suspected vulnerabilities to hello@isolicitude.com. Do not test against production systems without our written authorisation.