Security Policy
Last updated: 12 July 2026
This Policy describes the technical and organisational measures SLP Command applies to protect the confidentiality, integrity, and availability of user data, in accordance with Article 32 GDPR.
1. Authentication and access control
- User authentication is managed by a dedicated, industry-standard authentication provider. Passwords are never stored or transmitted in plain text; they are managed exclusively by our authentication provider using industry-standard hashing.
- All requests to protected endpoints require a verified authentication token. Requests without a valid token are rejected.
- Administrative access to operational dashboards requires both a verified user identity and an explicit administrator role, independently checked on every request. Administrative privileges are not self-assignable through any user-facing interface.
2. Data isolation
- Row-Level Security (RLS) is enforced at the database layer across all tables containing user data, ensuring that a user can only access their own records, independent of application-layer logic.
- Security-sensitive tables (including the security audit trail) grant zero direct read or write access to client applications; they are accessible exclusively through server-side, privilege-checked processes.
3. Encryption
- All data in transit between the application, our backend, and our sub-processors is encrypted using TLS/HTTPS.
- Data at rest is encrypted by our infrastructure and database providers in accordance with their respective security certifications.
4. Abuse and rate limiting
- API rate limiting is applied to reduce the risk of automated abuse, scraping, and credential-stuffing attacks.
- Failed authentication attempts and other security-relevant events are recorded in a dedicated, access-restricted security audit trail (see the Data Retention Policy).
5. Vulnerability and error monitoring
- Application errors and crashes are monitored through a dedicated diagnostics provider. Request bodies and authorization headers are stripped before transmission to this provider; no personal content, audio, or written responses are ever included in diagnostic data.
- We conduct periodic internal security reviews of new features before release, including authentication, authorisation, and data-exposure checks.
6. Responsible disclosure
If you believe you have discovered a security vulnerability in the Service, please report it responsibly to security@slpcommand.com. We commit to:
- acknowledging your report within 5 business days;
- investigating in good faith and keeping you informed of material progress;
- not pursuing legal action against good-faith security researchers who report vulnerabilities through this channel without exploiting them beyond what is necessary to demonstrate the issue.
7. Incident response
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR.
8. Sub-processor security
We select sub-processors that maintain industry-recognised security practices and are bound by data processing agreements requiring appropriate technical and organisational measures. See the Subprocessors page for the complete list.
SLP Command will never ask for your password by email, support chat, or any channel other than the official in-app login screen.
9. Contact
security@slpcommand.com