Security Policy & Infrastructure
Security-First Architecture for Legal Professionals
BundleCreator.co implements defence-in-depth security aligned with banking-level standards. Your sensitive legal documents are protected by multiple layers of encryption, access controls, and monitoring that meet or exceed industry requirements. Our security measures are guided by our Data Principles, ensuring security by design in every aspect of our platform.
🔐 Multi-Factor Authentication (MFA) - Enhanced Protection
As part of our commitment to protecting Legal Professional Privilege, Multi-Factor Authentication will be mandatory for all users from launch day (5th November 2025).
Supported Methods
- ✓ Authenticator apps (Google, Microsoft, Authy)
- ✓ SMS verification for accessibility
- ✓ Backup codes for recovery
- ✓ Hardware token support (coming soon)
Protection Benefits
- ✓ Prevents unauthorised account access
- ✓ Protects privileged legal documents
- ✓ Meets insurance requirements
- ✓ Aligns with SRA & BSB guidance
MFA adds a critical additional security layer, ensuring that even if credentials are compromised, your legal documents remain protected.
ISO 27001:2022 & SOC 2 Type II Compliance Preparation
BundleCreator.co is in advanced preparation for ISO 27001:2022 and SOC 2 Type II certification, demonstrating our commitment to the highest international security standards.
ISO 27001:2022 Preparation
Implementing comprehensive ISO 27001:2022 controls
All Annex A controls assessed and implemented
SOC 2 Type II Preparation
Implementing SOC 2 Trust Services Criteria
Trust Services Criteria aligned and documented
Comprehensive Assessment: All ISO 27001:2022 Annex A controls assessed and implemented. Beta trial runs 3rd November - 27th November 2025. Working towards ISO 27001 and SOC 2 Type II certification.
Verified Infrastructure Certifications:
- • Database Infrastructure: SOC 2 Type II & ISO 27001 certified
- • Google Cloud Platform: SOC 2, ISO 27001, ISO 27017, ISO 27018 certified
- • Authentication Service: SOC 2 Type II certified
- • Payment Processing: PCI DSS Level 1, SOC 2, ISO 27001 certified
1. Comprehensive Encryption Architecture
Your documents are protected with AES-256 encryption at rest and TLS 1.3 in transit, designed to meet UK GDPR requirements for data protection.
1.1 Transport Encryption
- Protocol: TLS 1.3 (TLS 1.2 minimum) with perfect forward secrecy
- Certificate: Extended Validation (EV) SSL certificates
- HSTS: Strict Transport Security enforced (2-year duration)
- Certificate Pinning: Prevents man-in-the-middle attacks
1.2 Storage Encryption (At Rest)
- At Rest: AES-256 encryption for all stored data via cloud database infrastructure
- Database: Transparent Data Encryption (TDE) enabled
- Backups: Encrypted with separate keys, rotated quarterly
- Key Storage: Hardware Security Modules (HSM) for key management
1.3 PDF Password Protection
- Technology: Browser-based PDF password protection
- Process: Password protection applied in your browser for exported bundles
- Use Case: Secure external sharing of completed bundles
- Benefit: Control access to exported PDF bundles when sharing with third parties
1.4 Client-Side Bundle Creation (Privacy-Preserving Architecture)
BundleCreator implements a privacy-preserving architecture where bundle PDFs are created entirely on your device in your browser, ensuring the server never sees your assembled bundle contents.
- Browser-Based Processing: Bundle creation occurs entirely in your web browser
- Zero Server Knowledge: The server stores encrypted documents but cannot access bundle contents during assembly
- Legal Privilege Protection: Maximum protection for Legal Professional Privilege - assembled bundles never traverse our servers
- Client-Side Password Protection: Optional AES-256 password encryption applied in your browser before export
- User-Only Access: Only you have access to the decrypted bundle and optional password
Technical Process:
- Encrypted documents downloaded from secure storage to your browser
- Browser-based processing decrypts and assembles bundle entirely on your device
- Optional AES-256 password protection applied in browser
- Exported bundle saved directly to your device
- Server never has access to assembled bundle contents
This architecture provides the highest level of confidentiality for sensitive legal documents, exceeding the security of traditional cloud-based document assembly systems.
2. Zero-Trust Access Control Framework
2.1 Row Level Security (RLS)
- Database-Level Isolation: Each user's data is isolated at the database level using Row-Level Security (RLS) policies
- Policy Enforcement: Access policies evaluated on every query, not just at application level
- Granular Permissions: Document-level access controls with viewer/editor/owner roles
- Audit Trail: Every access attempt logged with timestamp, user ID, and action performed
2.2 Authentication Security
Multi-Factor Authentication (MFA) will be enforced for all accounts at launch (5th November 2025) providing an essential additional security layer for Legal Professional Privilege protection.
- Provider: Enterprise authentication service with SOC 2 Type II certification
- Multi-Factor Authentication (MFA):
- TOTP (Time-based One-Time Password) via authenticator apps
- SMS verification for accessibility
- Backup codes for account recovery
- Mandatory enforcement at launch for all users
- Additional protection for privileged legal documents
- Session Management: Secure, httpOnly, sameSite cookies
- Password Policy: Minimum 8 characters with complexity requirements (uppercase, lowercase, number, special), plus privacy-preserving breach detection via HaveIBeenPwned k-Anonymity API
- Account Lockout: Progressive delays after failed attempts
2.3 API Security
- Rate Limiting: Intelligent rate limiting per user and IP
- CORS Policy: Strict origin validation
- API Keys: Scoped, time-limited tokens with automatic rotation
- Request Signing: HMAC-SHA256 request signatures
3. Infrastructure & Network Security
3.1 Cloud Infrastructure & Data Residency
🇬🇧 UK Data Residency
Primary data storage and processing occurs within the United Kingdom. Document data is primarily stored in UK data centres, though encrypted edge caching may temporarily store data in other locations for performance.
- Primary Data Center: London, UK (EU-West-2 region)
- Application Hosting: Vercel Edge Network with UK edge locations
- Backup Storage: UK-based disaster recovery facilities
- DDoS Protection: DDoS mitigation at the edge
- WAF: Web Application Firewall with custom rules for legal sector
3.2 Network Security
- Network Isolation: Private subnets for database and internal services
- Firewall Rules: Principle of least privilege, deny by default
- VPN Access: Required for administrative functions
- Intrusion Detection: Real-time monitoring with automatic response
3.4 Deployment Flexibility (Enterprise Solutions)
Yes, we're cloud-based but we don't have to be
Contact us about our Enterprise solutions.
Our technology can be housed within your secure environment, for the ultimate assurance.
While BundleCreator is cloud-based by default, we understand that some organisations require on-premise or private cloud deployments for the ultimate assurance:
Enterprise Deployment Options:
- Private Cloud Deployment: Deploy BundleCreator within your own AWS, Azure, or Google Cloud environment
- On-Premise Installation: Full installation within your data centre infrastructure with complete control
- Hybrid Solutions: Combine cloud convenience with on-premise security for specific workflows
- Air-Gapped Deployments: Available for organisations with strict data sovereignty requirements
Control & Compliance:
- Your Infrastructure: Complete control over hosting, backups, and data residency
- Your Security Policies: Integrate with your existing security infrastructure and policies
- Compliance Flexibility: Meet specific regulatory or contractual requirements
- Same Privacy-Preserving Architecture: Client-side bundle creation regardless of deployment model
Contact Us: For enterprise and on-premise deployment options, contact enterprise@bundlecreator.co
We deliver secure, state-of-the-art innovation with clean, modern designs.
Get in touch
Layered security tailored for your organisation's unique requirements
4. Continuous Monitoring & Threat Detection
4.1 Security Monitoring
- SIEM Platform: 24/7 security event monitoring and correlation
- Anomaly Detection: ML-powered detection of unusual access patterns
- File Integrity Monitoring: Real-time detection of unauthorised changes
- Vulnerability Scanning: Weekly automated scans, monthly penetration tests
4.2 Comprehensive Activity Logging
- User Actions: Every create, read, update, delete operation logged
- System Events: Authentication, authorisation, and configuration changes
- Log Protection: Tamper-proof logs with cryptographic signatures
- Retention: 365-day retention for compliance and forensics
4.3 Incident Response Plan
- Priority: Critical incidents addressed within 15 minutes
- Escalation Path: Clear chain of command to C-level
- Communication: Status page and direct client notifications
- Post-Incident: Detailed reports and remediation plans
5. Compliance & Security Standards
Compliance Framework
BundleCreator.co is designed and operated in compliance with:
- GDPR (EU 2016/679) - General Data Protection Regulation
- UK Data Protection Act 2018
- Legal Professional Privilege requirements
- UK Family Court Practice Direction 27A
Security Certifications & Compliance Programme
BundleCreator.co has completed comprehensive preparation for internationally recognised security certifications:
- ISO 27001:2022 - Working towards certification (formal audit scheduled Q2 2026)
- SOC 2 Type II - Working towards certification (Trust Services Criteria framework adopted)
- NCSC Cloud Security Principles - Fully aligned and implemented
- UK GDPR & Data Protection Act 2018 - Comprehensive compliance programme
November 2025 Update: We have implemented security policies, procedures, and controls based on ISO 27001:2022 Annex A framework. Beta trial period: 3rd November - 27th November 2025. Formal certification audits are scheduled for Q2 2026.
6. Advanced Security Features
6.1 HaveIBeenPwned-Integrated Password Security
🔐 HaveIBeenPwned Integration with k-Anonymity
We're one of the few legal tech platforms that actively checks passwords against known data breaches while maintaining complete privacy. Your password never leaves your device - we use k-Anonymity to check breach status without exposing it.
- Password hashed locally in your browser
- Only partial hash sent for checking (first 5 characters)
- Comparison done locally against returned results
- Zero knowledge of your actual password
6.2 Document-Specific Security
- Virus Scanning: Real-time scanning of all uploaded documents
- Malware Detection: Sandboxed analysis of suspicious files
- Format Validation: Strict validation prevents malformed file attacks
- Secure Redaction: Permanent redaction with audit trail
6.3 Data Loss Prevention
- Automated Backups: Hourly snapshots, daily backups, weekly archives
- Geographic Redundancy: Backups stored in separate regions
- Point-in-Time Recovery: Restore to any point within 30 days
- Secure Deletion: Multi-pass overwriting exceeds DoD 5220.22-M
6.3 Legal Sector Specific
- Privilege Protection: Technical controls prevent inadvertent waiver
- Court Compliance: Automatic compliance with e-filing security requirements
- Litigation Hold: Automatic preservation when triggered
- Chain of Custody: Cryptographic proof of document integrity
7. Security Team & Governance
7.1 Security Leadership
- Chief Information Security Officer: Direct report to CEO
- Security Team: Dedicated professionals, not shared responsibility
- External Advisors: Quarterly reviews by independent experts
- Board Oversight: Monthly security briefings to board
7.2 Security Culture
- Training: Monthly security awareness for all staff
- Background Checks: Enhanced DBS checks for all employees
- Code Reviews: Mandatory security review for all changes
- Vulnerability Disclosure: Published coordinated disclosure policy at /security/disclosure with UK Computer Misuse Act safe harbour
8. Our Security Commitments to You
✓Transparency: Annual security audits published publicly
✓Notification: Security incidents disclosed within 72 hours
✓No Backdoors: We will never create backdoors or weaken encryption
✓Legal Protection: We will challenge unlawful data requests
✓Continuous Improvement: Security is never "done" - we continuously enhance
Security Contact Information
Report Security Issues:
security@bundlecreator.co
PGP key available on request - enables encrypted communication for reporting sensitive vulnerabilities, ensuring your security reports remain confidential even if email is intercepted
Coordinated Vulnerability Disclosure: We welcome responsible security research. Our full Vulnerability Disclosure Policy is published at /security/disclosure — please read it before testing. It sets out safe harbour under the Computer Misuse Act 1990, in-scope and out-of-scope systems, data-handling rules, and our response SLAs (72-hour acknowledgement, 5-business-day triage).
We do not pay financial rewards for security research. What we offer is public recognition as a Defender of Access to Justice (with your consent), a signed certificate of contribution from the founder, and our sincere thanks.
🔐 Why PGP Encryption Matters for Security Reports
When reporting critical vulnerabilities, PGP (Pretty Good Privacy) encryption provides:
- End-to-end encryption: Your vulnerability report is encrypted on your device and can only be decrypted by our security team
- Protection against interception: Even if emails are compromised during transmission, the vulnerability details remain secure
- Proof of authenticity: Digital signatures verify the report comes from you and hasn't been tampered with
- Emergency security: In case of active exploitation, PGP ensures attackers cannot intercept and suppress vulnerability reports
- Responsible disclosure: Protects both you and us during the disclosure process, maintaining confidentiality until patches are ready
To obtain our PGP key: Email security@bundlecreator.co with subject "PGP Key Request" and we'll provide our public key upon request.
Related Documents
Our security policy works in conjunction with our other policies to ensure comprehensive protection:
- Our Data Principles - Core principles guiding all data handling and security decisions
- Privacy Policy - How we collect, use, and protect your personal information
- Data Retention Policy - How long we keep data and when we delete it
- Terms of Service - Legal terms governing use of our services
Last Updated: 24/07/2026
Version: 2.0
Next Review: 22/10/2026