Legal
Security Overview
Last updated: 15 June 2026. This document is maintained centrally by Ffon Solutions Limited.
Security Overview
Effective date: 15 June 2026
We take the security of E-Dob and the data entrusted to us seriously. This overview describes, at a high level, the measures we have in place. It is intentionally a summary and does not disclose sensitive architectural detail.
Infrastructure
E-Dob runs on Laravel Cloud (built on AWS), a SOC 2 Type 2 certified platform, with primary infrastructure in the UK/EU region (, London). Edge protection, CDN and a web application firewall (WAF) are provided by Cloudflare.
Encryption
- In transit: all traffic is encrypted using TLS.
- At rest: data is encrypted at rest via the underlying managed platform and object storage.
Access controls
- Role-based access control restricts what each user can see and do.
- Company data isolation ensures organisations can only access their own data.
- Two-factor authentication (2FA) is available to protect accounts.
- Account lockout is applied after repeated failed login attempts to deter brute-force attacks.
Application security
- A Content Security Policy (CSP) and other hardening headers are enforced.
- Input validation is applied throughout the application.
- We carry out regular dependency audits to identify and address known vulnerabilities.
- We operate security monitoring to detect and respond to suspicious activity.
Incident response
If you believe you have found a security vulnerability, please report it responsibly to security@e-dob.uk. We will investigate and respond promptly.
Our ongoing commitment
We conduct regular internal security reviews aligned with ISO 27001 principles as part of our ongoing security programme, and continue to invest in improving the security of the platform.
Central copy: view on the E-DOB Trust Centre →