Your website is hosted on Microsoft Azure and benefits from many advanced features.
Microsoft Azure
We partner with Microsoft Azure, which provides a secure, reliable and cloud-based hosting environment for our web platforms.
These servers are physically located in European data centres. Data is replicated across 2 availability zones in order to provide required resiliency.
Data Storage
Transactional data is stored in isolated Microsoft SQL Databases which are behind Azure’s firewall.
Keys to the database are stored in Azure’s Key Vault (encrypted). Our databases are managed by Microsoft, which means the servers and databases themselves are always up to date with the latest patches.
All of our databases are backed up multiple times every 5 minutes.
Only specific staff members are given access to administer our infrastructure; access is password controlled with 2-factor authentication.
Images and assets are stored in Azure’s Storage accounts which are only accessible with specific keys.
We do not store any credit card or banking details, these are held with our payment partners Stripe, GoCardless or PayPal.
Web Platform
Our web platform is hosted inside of Azure’s managed services - this allows us to dynamically scale and shrink with traffic. The infrastructure we are hosted on is always patched and secured with the latest updates thanks to Azure.
The Web Platform is built in ASP.NET which has lots of security benefits out of the box such as request validation along with rate limiting and IP blocking. Within our platform we communicate with the database over secure channels following best practices to ensure attacks such as SQL Injection can’t occur.
The web platform is backed up nightly and we are always running multiple copies to ensure not only uptime but to be able to handle any spike in traffic.
All of our production traffic is encrypted over an SSL connection (RSA 2048 bits) which ensures our end users are safe. Our platform receives an "A" security rating with SSL Labs .
We have 24/7 monitoring enabled which helps us keep an eye on site traffic, requests, errors and attacks. We can then take appropriate action if necessary to ensure the platform is stable.
