Legal

Security, and how to report a problem.

This page has two jobs. The first job is to describe how we protect what we hold. The second job is to show you how to report a security problem to us. Security work is our background. We would far rather hear about a problem than not hear about it.

Effective date: 13 August 2026.

There is very little here to attack.

This website is plain HTML, built by hand. There is no content system behind the pages. There are no plug-ins to keep patched. There is no login page and no admin area.

These pages reach no database, because these pages have none. Most website break-ins start at one of those places. This website does not have them.

Every page travels encrypted.

Every page is served over HTTPS. HTTPS scrambles the page between our server and your browser. Nobody on the network in between can read it or change it.

We also send a header called Strict-Transport-Security. That header tells your browser to use HTTPS for this site for a year. Plain, unencrypted HTTP is not an option after that first visit.

The browser is handed strict rules with every page.

Each page arrives with a content security policy. That policy is a list of rules your browser has to obey. The rules are short and tight.

Files. The browser may load files from this website only. Scripts are allowed from this website only. Each small script inside a page is matched against a fingerprint. A script that does not match will not run.

Framing and forms. No other website may load this site inside a frame. The contact form may only post back to this site. Embedded objects and plug-ins are blocked outright.

Everything else. Files are read as the type they say they are. The camera, the microphone and location are switched off for this site. A website you click through to is told only that you came from ours.

The contact form is checked on the server.

The form on this site is checked twice. Your browser checks it first. Our server then checks it again. The server check is the one that counts, because a browser can be bypassed.

The server accepts a message from our own site only. Every field has a length limit. The email address has to look like an email address. The phone field keeps digits and phone punctuation only. The form can send you back to a page on this site, and nowhere else.

Access is limited, and signing in takes two steps.

Only the people who need access to a system have access to that system. Nobody gets an account for a system they do not work on.

The accounts we use for hosting, email and client systems need more than a password. A second step is required at sign-in. A stolen password on its own is not enough to get in.

Your accounts and your data stay yours.

You own your website, your domain and your code from day one. Wherever we can, we build inside accounts that belong to you. Your data then sits in your account, and not in ours.

That matters most on the day you leave. You keep everything, and we hand back the keys. Nothing of yours is locked inside a system of ours.

Care plans cover updates, patches and backups.

A care plan covers hosting, updates, backups and changes. Software is patched as the fixes come out. Backups are taken, so a bad day means a restore instead of a rebuild.

Work without a care plan is different. There we do the job and hand it over. Updates and backups are then yours to run. We will say that plainly before the work starts.

A written agreement covers anything we handle for you.

Some of what we build holds personal information for a client. A booking system holding your customers' details is the usual example.

In POPIA terms you are the responsible party. We are the operator. Sections 20 and 21 of POPIA set out what an operator must do. An operator acts on your instruction only. An operator must also keep the information secure, under a written contract.

So we sign a written operator agreement before that work begins.

If something is ever compromised, here is what happens.

No set of measures stops everything. So we plan for the bad day as well.

First we contain the problem and stop the damage spreading. Then we tell the client, in plain language. We say what happened, what is affected, and what we are doing about it.

Section 22 of POPIA covers the step after that. Say personal information was reached by somebody with no right to it. The Information Regulator has to be told. The people affected have to be told as well. We do that as soon as section 22 requires.

Afterwards we write down the cause and the fix. You get that write-up too.

We hold no security certificate, and we claim none.

We hold no security certificate and no audit badge. We are not going to imply one. This page describes what we actually do, and nothing more.

How to report a security problem to us.

Have you found a weakness in this website, or in a site we host? Please email hello@trevern.com. Put the word Security in the subject line.

Tell us the address of the page. Tell us what you did, and what happened. A screenshot or a short recording helps a great deal. Add the date, the time and your time zone.

We reply within one working day. We tell you what we found. We keep you posted while the work is going on. We tell you when the problem is fixed. A person reads every report.

What we ask you not to do.

Please test gently. Please stay on the site you are reporting on.

Please do not run anything that slows a service down or takes it offline. Please do not open, change or delete anybody else's data. Reach data that is not yours, and the right move is to stop and tell us.

Please do not phone, email or message our people to trick them into giving access. Please leave our offices, our post and our hardware alone. Please do not run heavy automated scans against a client's systems.

There is no bug bounty, and no payment.

We do not pay for reports. There is no bug bounty here, and we would rather say so than let you assume one.

What you get is a fast reply, a real fix and a proper thank you. We will credit you by name if you would like that.

A good-faith report will not land you in trouble.

Follow this policy and act in good faith, and we will not take legal action against you. We will not report you for the testing this policy allows. We treat a report as help, because a report is help.

This applies to the testing described on this page. This does not apply to an attack, to theft of data, or to a demand for money.

Please give us a chance to fix it before you publish.

Give us a fair chance to fix a problem before you write about it publicly. We will agree a date with you and keep you updated. If a fix needs longer, we will tell you why.

We will not use this request to bury a report. Quiet is not the point. Getting the hole closed is the point.

This document explains how we work. It is not legal advice, and it does not replace advice from your own attorney.

Ask us the awkward questions.

Are you weighing us up as a supplier? Ask how your data would be held, and who would be able to reach it. A call answers that better than an email does.

Security reports go to hello@trevern.com. A person reads every one of them.

Book a free call

Free call · no obligation · one fixed quote in writing