01
Security approach
Security is considered across application development, access and operations, and controls evolve with the platform. No website or platform can guarantee absolute security.
02
Controls visible in this website codebase
- Server-side and client-side validation for the public contact form.
- Origin checking, honeypot protection, minimum completion time and request rate limiting for contact submissions.
- Secrets referenced through server environment variables rather than exposed in client code.
- Automated TypeScript, lint and production-build checks.
- Visible focus states, reduced-motion support and semantic page structure.
03
Data protection and architecture
Hosting, network, backup, encryption-at-rest and environment-separation details have not been approved for public disclosure. Controls must be documented against the deployed architecture before launch.
04
Account and access controls
Public login routes exist, but authentication implementation details such as multi-factor authentication, password controls, lockout and role enforcement were not verified in this website repository. No claim is made about them here.
05
Secure development
The website uses typed code, dependency management, input validation and server-side handling for protected delivery credentials. Formal development policies, review requirements and security testing schedules remain to be approved.
06
Infrastructure and service providers
Outbound contact delivery is designed to use a server-side email API when configured. A complete approved provider and subprocessor inventory is not available in this repository, so providers are not presented as a verified public list.
07
Monitoring, incidents and resilience
Monitoring, incident-response, notification, backup and recovery procedures must be verified against the deployed service. This page does not claim continuous monitoring, backup frequencies, geographic redundancy or recovery targets.
08
Payments and integrations
Payment and other integrations are subject to their providers’ controls, credentials and terms, and their TabTake availability varies. This page does not claim PCI DSS certification or that TabTake never handles payment data.
09
Customer responsibilities
- Use strong, unique credentials and protect authorised devices.
- Limit access to people who need it and remove former staff promptly.
- Review account activity and integration access.
- Keep provider credentials secure and report suspected compromise.
10
Reporting a vulnerability
Use the verified central contact address with the subject “Security report”. Include the affected page or component, reproduction steps, potential impact, evidence and safe contact details.
Do not access unrelated personal data, disrupt services, use social engineering or publish the issue before reasonable review. No bug bounty, safe-harbour commitment, reward or response time is promised.
11
Certifications and assurance
No ISO 27001, SOC 2, Cyber Essentials, PCI DSS, CREST, penetration-testing or other certification claim has been verified, so none is made.
12
Updates and contact
This overview may be updated as verified controls and platform capabilities develop. A dedicated security contact and policy review date remain pending approval.
Contact TabTake
Until specialist legal contacts are approved, use the verified central public address for questions about this page.
hello@tabtake.com