Security statement
How PollyHQ is built, run and protected.
Last updated 14 September 2026
Written for the person who wants to check before uploading a passport, and for the security team that will be asked to approve it. It names our suppliers, states what is in place, and says plainly what is not yet.
POLLYHQ LIMITED — registered in England and Wales, company number 17456463. Registered office: Redwings, Herons Farm Lane, Kirdford, RH14 0PR. Data controller for all member information.
Security, privacy and data protection contact: office@pollyhq.com
1. Encryption
- Everything between your browser and us travels over TLS 1.2 or above, with HTTPS enforced on every page and modern cipher suites only.
- Your records and uploaded files are stored encrypted at rest using AES-256 on managed, encrypted volumes.
- Backups are encrypted with the same standard, and are never stored unencrypted anywhere.
- Uploaded files sit in private storage. They are never reachable at a public address and open only through a signed link that expires after ten minutes.
2. Hosting and data location
The application, database and file storage run on Amazon Web Services infrastructure in the eu-west-1 (Ireland) region, under UK and EU data protection law. Pages are served through a global content delivery network, which carries only public website content — never your records or documents.
3. Access control
- Every record is bound to your household inside the database, enforced by row-level security policies rather than by the screens. A query that asks for another household's data returns nothing.
- Two-factor sign-in with a free authenticator app is available to everyone, and is required to add or open a passport, driving licence, ID card, visa, residence permit, health card or DBS certificate.
- Household sharing is invite-only and capped at four people. You can remove anyone at any time.
- Administrative functions sit behind a server-side role check held in a separate, protected table, so a role can never be granted from the browser.
- Passwords are stored only as salted hashes, and new passwords are checked against known breach lists and rejected if found.
4. Logging and monitoring
- Authentication events, database queries, server errors and outbound email are logged by the platform with restricted access and time-limited retention.
- Application errors are captured server-side for diagnosis, without recording document contents.
- A full member-facing audit trail (who viewed, changed or deleted a record) is on the roadmap below and is not yet in place — we would rather say so than imply otherwise.
5. Secret management
API keys, service credentials and signing keys are held in an encrypted secret store and injected into the server at run time. None is present in our source code, and none is ever sent to your browser. The only credentials visible in the browser are the public, read-restricted keys a web app must expose, which carry no privileges of their own.
6. Backups and retention
- The database is backed up automatically on a daily cycle, encrypted at rest.
- When you delete a record, it and its file go immediately. When you delete your account, everything goes immediately and permanently, and routine backups containing it age out within 30 days.
- Payment and accounting records are kept only as long as tax law requires, held apart from your documents.
7. Suppliers we rely on
These are the only third parties that touch member information. Each acts on our written instructions and cannot use your data for its own purposes.
- Amazon Web Services (Ireland) — hosting for the application, database and encrypted file storage. Compliance programmes.
- Google (Gemini models) — reads the document you upload, and the extracts from your own policies when you ask a question, so it can answer. Used through a paid enterprise route where your content is not used to train models. Security overview.
- DVSA (UK government) — receives a vehicle registration you enter and returns official MOT dates and mileage. No personal data is sent.
- Amazon Web Services (SES) — delivers your reminders and account emails. Receives your email address and the message we send you, nothing else.
- Stripe — will take membership payments when paid plans open. Card details go directly to Stripe and never reach us. Security at Stripe.
Where a supplier processes information outside the UK or EEA, the transfer is covered by approved safeguards such as standard contractual clauses.
8. Incident response
- If we detect or are told of a security incident, we investigate immediately, contain it, and preserve what we need to understand it.
- Where personal data is affected, we notify the Information Commissioner's Office within 72 hours of becoming aware, and tell affected members without undue delay — what happened, what it means for you, and what to do.
- We publish a plain summary afterwards rather than letting it pass quietly. Notifications go by email to the address on your account.
9. Reporting a vulnerability
If you believe you have found a security flaw, please tell us at office@pollyhq.com with enough detail to reproduce it. We aim to acknowledge within two working days and to keep you updated until it is closed.
We will not pursue anyone who reports in good faith, avoids privacy violations and data destruction, uses only their own test account, and gives us a reasonable chance to fix the issue before going public. Please do not run automated scanning that degrades the service for members.
10. Independent assurance — where we actually are
Being straightforward about this matters more than sounding certified. Today, no independent audit of PollyHQ is complete. Everything described above is built and running, but it is our own account of it. Our stated plan and target dates:
- Independent penetration test by an external security firm — target December 2026, with a summary letter available to members and organisations on request.
- Cyber Essentials Plus certification — target March 2027.
- ISO 27001 (or SOC 2 Type II where a customer prefers it) — readiness work through 2027, aiming to be audited by December 2027.
- Member-facing audit trail and enforced household-wide two-factor options — alongside the above.
These are targets, not achievements, and we will update this page as each is reached rather than in advance of it. Our written security position is available in full on request.
11. What we are not
PollyHQ is not an insurer, an insurance broker or a financial adviser, and is not authorised or regulated by the Financial Conduct Authority. We do not sell, arrange or recommend insurance, we do not approach insurers on your behalf, and we receive no commission from anyone. Our answers explain your own documents so you can act on them yourself.
