Security & Compliance
Effective Date: September 19, 2026
At Ardcast Services Limited, security is treated as a first-class feature. This page outlines our approach to application security, infrastructure protection, and compliance to ensure your data remains safe.
Infrastructure Security
All Ardcast services are hosted on world-class, ISO 27001 and SOC 2 compliant cloud providers. We do not host physical servers or maintain hardware on our premises.
- Encryption in Transit: All communications between your browser and our servers are encrypted via industry-standard TLS 1.3.
- Encryption at Rest: All sensitive databases and backups are encrypted at rest using AES-256 encryption.
Application Security
Our software development lifecycle includes security at every phase:
- Framework Security: We utilize modern frameworks that provide built-in protections against OWASP Top 10 vulnerabilities, including Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and SQL Injection.
- Authentication: We use secure, salted, and peppered password hashing algorithms (Argon2i/Bcrypt) and enforce strict session management.
Compliance & Privacy
We adhere to a "Privacy First" approach, directly influencing our security posture. By collecting minimal data, we inherently reduce risk.
- GDPR Compliance: We comply with the UK and EU GDPR, ensuring data minimization, right to erasure, and strict processing boundaries.
- No Third-Party Tracking: As outlined in our Cookie Policy, we do not inject third-party advertising scripts, eliminating a major vector for third-party data leakage.
Vulnerability Reporting
We welcome responsible disclosure from the security research community. If you believe you have found a security vulnerability in any Ardcast service, please report it immediately.
Please email reports to: security@ardcast.com
We ask that you do not publicly disclose the issue until we have had a reasonable timeframe to investigate and patch the vulnerability.
Note: We do not currently offer a monetary bug bounty program, sorry.