Protection Research

Security & Privacy Overview

Effective Date: 3 August 2026

Contents

  • Introduction
  • About Protection Research
  • Security Principles
  • Infrastructure & Hosting
  • Authentication & Access Control
  • Encryption
  • Secure Development
  • Vulnerability Management
  • Monitoring & Incident Response
  • Business Continuity
  • Privacy & Data Protection
  • Sub-processors
  • Customer Responsibilities
  • Contact

1. Introduction

This Security & Privacy Overview provides a high-level summary of the security and privacy practices implemented by Protection Research Ltd ("Protection Research", "we", "our" or "us"). This document is intended to assist customers, prospective customers and business partners in understanding the organisational, technical and operational measures we implement to help protect our Services and the information entrusted to us.

This overview should be read alongside our:

Information Security Policy;

Privacy Policy;

Data Processing Agreement;

Responsible Vulnerability Disclosure Policy; and

Business Continuity & Disaster Recovery Policy.

2. About Protection Research

Protection Research Ltd is a UK-based software company providing business protection research Software-as-a-Service (SaaS) solutions for authorised financial advisers and their firms. We are committed to protecting the confidentiality, integrity and availability of our Services through appropriate technical and organisational measures. Security and privacy considerations form part of our ongoing operational processes and product development lifecycle.

3. Security Principles

Our approach to information security is guided by the following principles: Security by design. Least privilege access. Defence in depth. Risk-based decision making. Continuous improvement. Protection of customer information. Responsible vulnerability management. Compliance with applicable legal and regulatory requirements. These principles underpin our policies, operational procedures and technical controls.

4. Infrastructure & Hosting

Protection Research delivers its Services using professionally managed cloud infrastructure. Our infrastructure is designed to support: availability; resilience; scalability; secure administration; monitoring; and regular maintenance. Where appropriate, infrastructure components are protected using security controls such as: network segmentation; firewalls; secure administrative access; system hardening; security updates; and infrastructure monitoring. Infrastructure configurations are reviewed periodically as our Services evolve.

5. Authentication & Access Control

Access to systems and information is controlled using the principle of least privilege. Security measures include, where appropriate: unique user accounts; role-based permissions; restricted administrative access; periodic access reviews; secure account provisioning and deprovisioning; strong authentication requirements; and multi-factor authentication for privileged accounts where supported. Access is granted only where required for legitimate business purposes.

6. Encryption

Protection Research uses industry-recognised cryptographic controls to help protect information during transmission and, where appropriate, while stored. Our encryption practices may include:

Transport Layer Security (TLS) for communications over public networks;

  • encryption of sensitive data at rest where appropriate
  • secure management of cryptographic keys
  • encrypted backups where practicable
  • encryption of administrative communications where supported; and

periodic review of cryptographic standards and implementations. Encryption controls are selected based on the sensitivity of the information being protected and recognised industry good practice.

7. Secure Development

Security is incorporated throughout our software development lifecycle. Our development practices may include: secure system design; code review processes where appropriate; dependency management; vulnerability scanning; security testing before production deployment where practicable; change management procedures; separation of development and production environments where appropriate; and timely application of security updates. Security considerations are integrated into product planning, implementation and ongoing maintenance.

8. Vulnerability Management

Protection Research maintains processes for identifying, assessing and addressing security vulnerabilities affecting our Services. Our approach may include: monitoring security advisories; reviewing emerging cyber threats; assessing reported vulnerabilities; prioritising remediation activities according to risk; applying security patches where appropriate; verifying remediation actions; and continually improving our vulnerability management processes. We also maintain a Responsible Vulnerability Disclosure Policy to enable security researchers to report vulnerabilities responsibly and in good faith.

9. Monitoring & Incident Response

Protection Research maintains operational monitoring appropriate to the Services we provide.

Monitoring activities may include:

  • infrastructure monitoring
  • application monitoring
  • authentication event monitoring
  • operational logging
  • security event monitoring; and

service health monitoring. Where a security incident is identified, we follow documented procedures designed to: identify and assess the incident; contain potential impacts; investigate root causes; restore affected services where necessary; notify affected customers where legally or contractually required; and implement improvements to reduce the likelihood of recurrence. Our incident response processes support the ongoing resilience and security of our Services.

10. Business Continuity

Protection Research maintains business continuity and disaster recovery arrangements designed to support the continued operation of our Services.

These arrangements may include:

  • secure backup procedures
  • recovery planning for critical systems
  • infrastructure resilience
  • restoration testing where appropriate
  • periodic review of recovery procedures; and

continual improvement of operational resilience. Our objective is to minimise disruption and restore normal service operations as efficiently as reasonably practicable following significant operational events.

11. Privacy & Data Protection

Protection Research is committed to protecting personal data and processing it in accordance with applicable data protection legislation, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our approach to privacy includes: processing personal data lawfully, fairly and transparently; collecting only the personal data necessary for legitimate business purposes; implementing appropriate technical and organisational security measures; restricting access to authorised personnel; retaining personal data only for as long as necessary; and supporting the rights of data subjects in accordance with applicable law. Further information about how we collect, use and protect personal data is available in our Privacy Policy and, where applicable, our Data Processing Agreement.

12. Sub-processors

Protection Research may engage carefully selected third-party service providers ("Sub-processors") to support the delivery of our Services.

Examples of services that may be provided by Sub-processors include:

  • cloud infrastructure and hosting
  • payment processing
  • transactional email delivery
  • authentication and identity services
  • customer support tools
  • monitoring and logging services; and

backup and disaster recovery services. Where a Sub-processor processes personal data on our behalf, we seek to ensure that appropriate contractual and organisational safeguards are in place to protect that information. A current list of Sub-processors is maintained separately and is available upon request or through our published Sub-processor List.

13. Customer Responsibilities

While Protection Research implements appropriate security measures to protect our Services, security is a shared responsibility.

Customers are responsible for:

  • maintaining the confidentiality of account credentials
  • implementing appropriate security controls within their own environment
  • enabling multi-factor authentication where available
  • keeping authorised user information up to date
  • protecting devices used to access our Services
  • complying with applicable laws and regulations
  • promptly reporting suspected security incidents affecting their account; and

ensuring that their use of our Services complies with our Terms of Service and Acceptable Use Policy. Customers should regularly review their own security posture and implement appropriate organisational and technical controls to address risks within their own environments.

14. Contact

Questions regarding our security or privacy practices may be directed to:

Protection Research Ltd

Company Number: 17366537

  • Registered Office: 41 Colwyn Road, Stockport, Cheshire, England, SK7 2JG
  • Email: support@protectionresearch.com

End of Security & Privacy Overview

Effective Date: 3 August 2026

© Protection Research Ltd. All rights reserved.