First draft — v0.1, not yet legally reviewed, not published. Every document on this site must be reviewed by a solicitor before it is relied on. See the status note on the home page.

Security

Last updated: [PUBLISH DATE] · Version: 0.1 (first draft — not yet legally reviewed, not yet published)

This is a first draft, not yet legally reviewed or published. It reflects genuine, currently-implemented controls only, backed by the fuller internal Information Security Policy (available on request to enterprise customers or insurers). We only state controls that are actually in place. Where something is planned but not yet built, it's marked as such rather than implied.

Access control

Data protection in transit and at rest

Application security

Vulnerability reporting

Found a security issue? Email security@hostable.games. We aim to acknowledge within 3 business days. Please don't publicly disclose before we've had a chance to respond — a fuller responsible-disclosure / bug-bounty policy is not yet written.

Incident response

We maintain an internal Incident Response Plan covering detection, containment, notification, and post-incident review, backed by an internal breach register that records every incident — whether or not it was reportable — for accountability purposes. If a breach affecting your personal data occurs, we'll notify you and, where required, the ICO, without undue delay.

What's not yet in place

In the interest of not overstating our posture:

↑ Back to top