Security Overview
Last updated: · Last reviewed:
Last updated: 31 August 2026
Our approach
Lydmera applies technical and organisational measures intended to provide security appropriate to the personal data and service risks. Security is an ongoing process; no internet service can guarantee absolute security.
This summary is not a certification or service-level agreement. Lydmera does not claim a particular certification, uptime, recovery time, backup period or vulnerability-response time through this page.
Measures
Lydmera’s security approach includes:
- HTTPS/TLS protects supported connections between users and the Service;
- managed hosting, database, authentication and storage providers supply relevant infrastructure controls under contract;
- production access is limited to authorised people and services on a need-to-use basis;
- privileged provider and administrative access uses strong authentication and available multi-factor controls;
- secrets and credentials are kept outside public source code and restricted to the services that need them;
- application, provider and authentication information needed for security and fault investigation is retained for a limited operational period;
- reported and identified material vulnerabilities are assessed and addressed according to risk; and
- an incident process covers assessment, containment, recovery, evidence, notification and lessons learned.
Infrastructure providers may hold their own certifications and independent audit reports. Those are controls of the relevant provider and are not certifications held by Lydmera Limited.
Personal-data incidents
We assess suspected personal-data incidents and make notifications required by the law applicable to our role.
- Where Lydmera is a controller, the Guernsey law generally requires notification to the ODPA within 72 hours after awareness unless the breach is unlikely to create the relevant risk; affected people are notified as soon as practicable where the required high-risk threshold is met.
- Where Lydmera is a processor for Customer Content, we notify the relevant Customer without undue delay and provide information reasonably needed for the Customer’s assessment.
The 72-hour period principally concerns regulator notification. It does not mean that every affected customer or person will be notified within 72 hours; the applicable role, legal threshold and risk determine the required notice.
Customer responsibilities
Customers should use unique credentials, protect email accounts and devices, restrict Account access, remove former users, verify sharing/export destinations and report suspicious activity promptly. Customers should not place highly regulated or unnecessary personal data in Customer Content without an agreed workflow.
Responsible disclosure
Report a suspected vulnerability to security@lydmera.com with a clear description, affected URL/feature and safe reproduction steps.
Researchers must:
- avoid privacy violations, persistence, data destruction and service disruption;
- use their own Account and data;
- stop if they encounter another person’s data;
- not use denial-of-service, social engineering or physical intrusion;
- not demand payment or threaten disclosure; and
- allow reasonable time for investigation before public disclosure.
We will review good-faith reports and will not pursue a researcher solely for accidental, proportionate activity that follows these rules, but this is not permission to breach law, access other people’s data or disrupt the Service. No bounty is promised.
Requests
- Security report: security@lydmera.com
- Privacy or data-processing question: privacy@lydmera.com
- Current providers and subprocessors: see the Subprocessors page
Any customer-specific security commitment, SLA, audit right or recovery target must be in a signed Business order form or DPA, not inferred from this overview.