Security
Last updated 25 June 2026
AKdev Ltd takes the security of our products and the data they hold seriously. This page summarises how we protect data across all AKdev apps and services and how to report a problem.
How we protect data
- Data is encrypted in transit using TLS, and at rest where supported by our providers.
- Access to data is scoped per user – accounts can only reach their own data – and access to production systems is restricted to what is necessary to operate the Services.
- We host on reputable infrastructure providers and keep dependencies patched and up to date.
- We apply the principles of least privilege and data minimisation across our systems.
- Your data is backed up by our infrastructure providers so it can be recovered after a failure.
Data breaches
If a personal-data breach occurs that is likely to affect you, we will notify the Information Commissioner’s Office and, where required, the people affected, in line with our obligations under the UK GDPR. See our Privacy Policy for how we handle your personal data.
Reporting a vulnerability
If you believe you have found a security vulnerability in any AKdev product, please email security@ak.dev with details and steps to reproduce. The same address is published in our security.txt. We aim to acknowledge your report within five business days, will keep you updated as we investigate, and ask that you give us a reasonable opportunity to fix the issue before any public disclosure.
Scope. This invitation covers products and services that AKdev controls – our apps, websites, and the API endpoints we operate. It does not extend to the infrastructure of our providers (for example Supabase, Vercel, or Google), which you are not authorised to test; please report any concern about those to us and we will take it up with them. Out of scope: denial-of-service or load testing, social engineering of our staff or users, physical attacks, and anything that accesses, modifies, or deletes data that is not your own.
Safe harbour. We authorise good-faith security research carried out within the scope above, and we will not treat it as unauthorised access for the purposes of the Computer Misuse Act 1990 or pursue legal action over it, provided you respect user privacy, avoid service disruption, act only within scope, and give us a reasonable chance to remediate before disclosing. If in doubt about whether something is in scope, ask us first at security@ak.dev.
Contact
Security questions or reports: security@ak.dev.
