Skip to content
ANB Codes

Trust

Security and data

Last updated 4 October 2026

Clients trust us with their customers' data, their code and their accounts. This page explains how we look after all three, in your projects and in our own systems.

Before any work starts

  • NDA first. We sign your NDA, or send ours, before you share anything sensitive.
  • Data processing agreement. Contracts are under English law and include a data processing agreement under UK GDPR whenever we handle personal data for you.
  • Your accounts, in your name. Code repositories, hosting, domains and app store accounts are set up in your name. We work through access you grant and can remove at any time.

Where data is hosted

For your project, we agree the hosting region with you before launch, for example the UK or EU for data covered by GDPR. We use established cloud providers, with the accounts in your name.

Our own client portal stores its records and files in a database in London, United Kingdom. Files are kept in private storage and are only shared through short-lived links after you sign in.

Who can see what

  • Least access. Only the people working on your project get access to it, and only to the systems they need.
  • Separated by design. In our client portal, database rules make sure each client can only read their own projects, invoices, files and messages.
  • A record of changes. Staff actions in the portal, such as creating accounts or resetting passwords, are written to an activity log.
  • Encrypted in transit. Our website and portal are served only over HTTPS, and browsers are told never to fall back to an unencrypted connection.

Building secure software

  • We check permissions and input validation as we build, and keep libraries up to date.
  • Secrets such as API keys live in the hosting provider's encrypted settings, never in the code.
  • Forms are protected against spam and automated abuse.
  • On a care plan, we apply security patches and dependency updates every month and keep daily backups, with response times in writing.

Report a security issue

If you think you have found a vulnerability in anbcodes.com or a system we look after, email hello@anbcodes.com with “Security” in the subject. Please give us a reasonable time to fix it before telling anyone else, and don't access or change data that isn't yours. We will reply to let you know we're looking into it.

How we handle personal information is set out in our privacy notice.