
Public assurance.
Private controls.
This centre gives customers and reviewers useful evidence about how DPMINDS protects its services. Credentials, exploit paths, customer data, internal thresholds and administrative control surfaces remain private by design.
Controls designed around evidence and restraint
DPMINDS publishes the principles customers can assess while keeping operational details that could weaken security restricted.
Minimum necessary access
Administrative access is separated from customer access. Sensitive actions require authenticated, role-controlled paths and are recorded for review.
Fail-closed decisions
When required evidence is missing, stale or inconsistent, protected intelligence and release controls are designed to hold rather than assume safety.
Controlled releases
Production changes are versioned, integrity checked and deployed through a controlled release path with retained rollback evidence.
Evidence without secret leakage
Operational records preserve decision and integrity evidence while excluding passwords, tokens, customer secrets and unnecessary exception content.
Data minimisation
DPMINDS limits personal data to what is needed for identity, payment, licensing, learning, support, security and lawful service measurement.
Human accountability
Automated signals may block or prioritise work, but material customer, security and policy decisions remain attributable to authorised people.
Useful status, without invented uptime
DPMINDS does not currently publish or promise a contractual uptime percentage. We will not turn an unmeasured number into a marketing claim.
This declaration is tied to production release v364. Internal monitoring may identify and contain a condition before it is appropriate or safe to publish details here.
How material incidents are handled
- Detect and containProtect customers and preserve evidence first.
- Assess impactConfirm affected services, data and obligations.
- CommunicatePublish useful customer impact and actions without exposing attack paths.
- Learn and improveRecord corrective actions and publish a safe summary when appropriate.
Notification principle: where an incident materially affects customers, DPMINDS will use this centre and direct customer communications as appropriate. Regulatory notifications are assessed under applicable law.
Privacy is an operating constraint
We minimise collection, separate optional measurement from essential service functions, and explain the purposes and rights that apply.
Use the minimum information needed to secure accounts, fulfil services, support customers and meet legal obligations.
Sell personal data, store full card details, collect broker passwords or use profile photos for facial recognition.
Review choices and exercise eligible UK data rights through the full privacy declaration.
Report security concerns safely
If you believe you have found a vulnerability, contact DPMINDS privately before publishing it or testing beyond what is necessary to describe the concern.
Include
- the affected page, service or product;
- clear, reproducible steps and observed impact;
- only the minimum redacted evidence needed; and
- a safe way to contact you.
Boundaries
- do not disrupt services, deceive people or access another person’s data;
- stop testing if sensitive data is encountered;
- do not demand payment or use a finding to threaten disclosure; and
- allow reasonable time for validation and remediation.
DPMINDS does not currently operate a public bug-bounty programme or grant blanket authorisation for penetration testing. Good-faith reports made within these boundaries will be reviewed and prioritised according to risk.
Material external services, named plainly
This public summary identifies material providers that may receive data. The legal role depends on the service and contract; payment and platform providers may act as independent controllers.
| Provider | Purpose | Data in scope | Position |
|---|---|---|---|
| OpenAI Sites and Cloudflare | Web hosting, managed compute, storage, availability and security | Site, account and operational service data where applicable | Service infrastructure |
| Supabase | Customer authentication and account security | Account identifiers, authentication and security data | Service provider |
| Postmark | Transactional email and delivery events | Recipient, message content and delivery metadata | Service provider |
| Daily | Private live audio, video and screen-sharing rooms when enabled | Participant and room data; media intentionally shared in a room | Service provider |
| Voipfone | Business telephony and call routing | Telephone network and call-routing records | Service provider |
| Stripe and PayPal | Hosted payment, fraud-control and refund services | Checkout, payer and transaction data | May act as a separate controller for some services |
| Apple | Sign in with Apple, iOS distribution and Apple-managed purchases where used | Apple account, app and purchase data | May act as a separate controller |
Register reviewed 29 August 2026. DPMINDS assesses necessity, access, security and transfer safeguards as applicable. See the privacy declaration for the controlling public privacy notice.
No badges before evidence
Legal obligations, good-practice frameworks and independent certifications are different things. DPMINDS labels them separately.
Privacy obligations and risk-based controls; not a certification.
Identified as a future independent assurance milestone; certification has not been represented as underway or achieved.
DPMINDS does not claim ISO 27001 certification.
DPMINDS does not currently publish a SOC 2 report.
Material changes, without exposing attack paths
We publish changes that affect customer assurance, security posture or public commitments. Routine internal maintenance may not appear here.
Trust Centre published
Added public security principles, availability and incident position, responsible disclosure, material provider register, assurance status and security-focused release notes.
Self-forensic integrity recovery completed
Completed a controlled in-place upgrade, preserved concurrent ledger evidence, verified the installed release and restored accepted report delivery.