Last updated · May 19, 2026
Security & Data Handling
FraudRadar handles sensitive scam intelligence on behalf of regulated firms, brand owners, and consumer reporters. This document is maintained by FraudRadar and describes the technical and organisational measures we currently have in place to protect customer data. It is not an independent certification.
02Infrastructure
- Hosted on cloud infrastructure operated by providers that publish independent SOC 2 Type II and ISO/IEC 27001 reports for the underlying compute, storage, and networking layers we rely on.
- Production workloads run in private network segments; databases are not publicly reachable.
- Multi-zone deployment with automated failover within a primary region in the UK / EEA.
- Automated daily backups with point-in-time recovery for at least 7 days. Backups are encrypted and access-controlled.
- Production and non-production environments are fully separated, with no production data used in development or testing.
03Encryption
- In transit: TLS 1.2 or higher for all client and inter-service traffic, with HSTS enabled on customer-facing domains.
- At rest: AES-256 encryption for databases, object storage, queues, and backups.
- Passwords are stored as salted bcrypt hashes — never in plain text.
- Secrets, API keys, and signing keys are stored in a managed secret vault with audit logging and automatic rotation where supported.
- Customer-uploaded evidence is encrypted at rest and access is restricted to authorised investigators on a need-to-know basis.
04Identity and access control
- Role-based access control (RBAC) enforced at the database level via row-level security.
- Least-privilege access for FraudRadar staff; production access requires SSO with hardware-backed multi-factor authentication and is fully logged.
- Customer-facing multi-factor authentication is available and recommended; enterprise plans support SSO via SAML/OIDC.
- Automatic session expiry, refresh-token rotation, and immediate revocation on logout or suspected compromise.
- Periodic access reviews to ensure that staff and integrations retain only the privileges they need.
05Application security
- Input validation with schema enforcement on both client and server.
- Output encoding and parameterised queries to mitigate injection attacks.
- Modern HTTP security headers, including a strict Content Security Policy where compatible with embedded preview environments.
- Dependency scanning and automated patching of high and critical vulnerabilities, with prioritisation based on exploitability and exposure.
- Static application security testing (SAST) and software-composition analysis (SCA) in CI.
- Annual third-party penetration tests; executive summaries available under NDA on enterprise plans.
06Software development lifecycle
- All production changes flow through version control with mandatory peer review.
- Automated tests run on every change; production releases are tracked and reversible.
- Security review is part of the design process for features that touch authentication, authorisation, or sensitive data.
- Developers complete security training during onboarding and at least annually thereafter.
07Monitoring and logging
- 24/7 automated monitoring of platform health, error rates, and anomalous traffic.
- Centralised audit logs for authentication, role changes, admin actions, and access to customer data.
- Real-time alerting on suspicious activity such as credential stuffing, privilege escalation, and unusual data egress.
- Log integrity controls and retention aligned with our Privacy Policy.
08Incident response
FraudRadar maintains a documented incident response plan with named roles and runbooks for the most likely incident classes. In the event of a confirmed breach affecting customer personal data, we will notify affected account holders without undue delay and in any event within 72 hours of becoming aware, in line with UK GDPR Article 33.
- On-call rotation with documented escalation to engineering leadership and the data-protection lead.
- Post-incident reviews focus on root cause and systemic fixes, not individual blame.
- Customers are kept informed throughout an incident and receive a written post-mortem where appropriate.
Report suspected vulnerabilities or incidents to support@fraudradar.co.uk.
09Vendor and sub-processor management
We perform security and privacy due diligence on every sub-processor before granting them access to customer data, and we re-assess them at least annually. We require contractual commitments equivalent to our own, including data processing agreements, breach notification, and assistance with data-subject requests. A current list is available on request.
10People security
- Background checks during onboarding where permitted by law.
- Confidentiality agreements covering customer and platform data, surviving termination of employment.
- Documented joiner-mover-leaver processes to ensure access is granted, adjusted, and revoked promptly.
- Company-managed devices with full-disk encryption, automatic patching, EDR, and remote-wipe capability.
11Business continuity and disaster recovery
- Tier-1 service availability target of 99.9% measured monthly.
- Multi-zone deployment with automated failover and infrastructure-as-code re-provisioning.
- Disaster-recovery drills conducted at least twice per year, including full restore-from-backup exercises.
- Documented recovery time and recovery point objectives that are reviewed annually.
12Data segregation and tenancy
The Service is multi-tenant. Customer data is logically segregated at the application and database layer, with row-level security policies that prevent cross-tenant access. Enterprise customers with stricter requirements can request region-pinned deployment and dedicated infrastructure.
13Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please email support@fraudradar.co.uk with a clear description, reproduction steps, and any supporting evidence. Please do not test against other customers, exfiltrate data beyond what is necessary to demonstrate the issue, or publicly disclose before we have had a reasonable opportunity to remediate. We will acknowledge reports within 3 business days and credit researchers (with consent) in our release notes where appropriate. PGP key available on request.
14Your responsibilities
- Use a strong, unique password and never share it.
- Enable multi-factor authentication on your account.
- Verify your email and keep your contact details current to receive security alerts.
- Review your active sessions and sign out of devices you no longer use.
- Treat exported data and evidence with the same care you would your own production data.
- Report anything that looks suspicious — false positives are always welcome.
15Contact
Security questions and responsible-disclosure reports: support@fraudradar.co.uk. For commercial inquiries about enterprise security packages, including DPA execution and audit support, contact the same address and we will route the request to the appropriate team.