Security

How we keep your company's records safe: where they live, who can reach them, and what happens if something goes wrong.

Updated 9 October 2026

Hosting

Groundcuvva runs on Cloudflare’s network, which also absorbs denial-of-service attacks. Records live in a managed PostgreSQL database run by Neon on Amazon Web Services in London. Uploaded files are kept in private Cloudflare R2 storage and are only ever handed to a signed-in user who is allowed to see them. The full list of providers is on our sub-processors page.

Encryption

  • In transit: every page, API call and file download is served over HTTPS only. Browsers are told never to use plain HTTP for groundcuvva.com or any company address (HSTS).
  • At rest: the database, its backups and file storage are encrypted by the providers.
  • On top of that, the most sensitive fields (gate codes and key-safe notes, right-to-work notes and accident-book injury details) are encrypted by the application itself (AES-256-GCM) before they reach the database, with a key held separately from it.
  • Passwords are never stored, only salted hashes.

Access controls

  • Every company’s records are tagged with that company and every query is limited to the signed-in user’s company. Each company has its own web address.
  • Roles decide what people see: owners and admins run the account; crew see their own schedule and records; clients see only their own visit reports in the client portal.
  • Email addresses are verified, and sign-in, sign-up and password reset are rate-limited.
  • Sessions are short: three days, or one day without “keep me signed in”. Signing out clears offline copies of the schedule from the device.
  • Our own team can reach customer accounts only through a separate admin area, and only to support or secure the service.

Two-step sign-in

Anyone can turn on two-step sign-in with an authenticator app, with one-time backup codes for a lost phone. When it is on, an emailed sign-in link can’t be used to skip the code. It is mandatory for Groundcuvva’s own administrators. We recommend every account owner and admin turns it on.

Application security

  • Browser protections on every response: Content Security Policy, a ban on being framed by other sites, no content-type sniffing and a strict referrer policy.
  • Uploaded files are checked by content, not just by name. Anything that isn’t an image or PDF is only ever downloaded, never opened in the browser.
  • Dependencies are checked for known vulnerabilities and kept up to date.
  • Our workers.dev and preview addresses are switched off, so the app is only reachable through our own domain.

Audit logging

Each company has an activity log of who changed what, and an access log, visible to its owners and admins, of who opened HR records or the accident book and who downloaded personal data. Every action our administrators take is written to a separate audit log, with time, IP address and browser. Platform logs are kept to detect and investigate incidents, with sign-in tokens stripped from them.

Backups

The database is continuously backed up with point-in-time recovery for [BACKUP RETENTION, e.g. 7 days], so it can be restored to any moment in that window. Backups are encrypted and held by the database provider in the same region.

If something goes wrong

We follow a written breach response procedure. If a personal data breach affects your company’s data we will tell you without undue delay, and within 48 hours of becoming aware, with what we know and what we are doing, so you can meet your own 72-hour duty to notify the ICO. Where we are the controller, we notify the ICO ourselves within 72 hours when the law requires it. Details are in our data processing agreement.

Reporting a vulnerability

Found a security problem? Email privacy@groundcuvva.com with the details. Please give us reasonable time to fix it before telling anyone else, and don’t access other people’s data or disrupt the service while testing. We will reply, keep you updated, and credit you if you would like.