Skip to content

Security

How we look after your bookings.

What we actually do to keep Developing Today Appointments running and its data safe, described plainly. For what information we collect and why, see the privacy page.

Sign-in without passwords

  • You sign in with Microsoft (work, school or personal), Google or Apple. We never see or store a password.
  • Our server checks every sign-in token itself: who issued it, who it was issued for, that it is signed and that it hasn't expired.
  • The token lives only in your browser tab's session storage, so it goes when the browser session ends or you sign out.

Access checked on every request

  • Every request for an organization's data checks that the person signed in is staff of that organization or location.
  • An automated test calls every part of our API without signing in, and fails unless the only answers it gets are from the short list of public booking endpoints.
  • Public pages, such as the booking page, never send your staff's details to the browser, and our tests check that on every change.

Locked down in the browser

  • A strict Content Security Policy: no inline or injected scripts, and scripts only from our own site and the few services we name (sign-in, maps and Cloudflare's visit counts).
  • Pages can't be framed by other sites, browsers are told not to guess file types, and our address isn't leaked to other sites beyond the domain.
  • Our tests run every page under that policy and fail on any violation; any violation seen in real use is reported to us.

Hosting

  • The website is served by Cloudflare Pages, over HTTPS.
  • The API runs on our own server, which isn't open to the internet: it listens only on the machine itself, and traffic reaches it through an encrypted Cloudflare Tunnel.
  • The API's secrets are handed to it by the operating system and readable only by it, and its database account can read and write data but not change the database itself.

Backups

  • The database is backed up every night. Each backup is checked before it is kept, held for 14 days, and copied off-site to Microsoft Azure, encrypted with AES-256.

Monitoring

  • Errors and performance are reported to our own, self-hosted Sentry, not a third party's.
  • There are no session recordings, and no third-party analytics beyond Cloudflare's cookieless visit counts.
  • The server's traces and logs go to monitoring we run ourselves.

How changes are made

  • Every change goes through a pull request and must pass the automated checks before it can be released.
  • Those checks include the API's tests, end-to-end tests in a real browser, accessibility checks, static analysis (with every compiler warning an error), a dynamic security scan (OWASP ZAP), secret scanning and licence checks.
  • Dependencies are kept up to date, with updates tested by the same checks.

What we don't claim

We don't claim any formal security certification, such as SOC 2 or ISO 27001, for Developing Today Appointments. The practices above are what we do, described as they are. If your organization has a security questionnaire for its suppliers, email us and we'll answer it.

Reporting a vulnerability

If you think you've found a security problem, please email [email protected] with the details. Please don't test against other people's bookings or data.