HeroPerks

Platform Sub-Processors

A small number of third-party sub-processors are engaged in delivering platform services, listed below.


Current Sub-processors

Cloudflare

Role: TLS termination, edge network, traffic filtering, content delivery, and DDoS protection. Cloudflare acts as the TLS endpoint for all client connections — data in transit is encrypted at this layer before reaching the origin server.
Encryption: TLS 1.2/1.3 with AES-GCM cipher suites and forward secrecy via ECDHE key exchange
Data processed: IP addresses and request metadata only — no personal data stored
Location: Global infrastructure (no personal data stored)
Website: cloudflare.com


Big Wet Fish Hosting

Role: Managed server hosting, infrastructure, and server-level security
Data processed: All platform data, including user account data
Location: United Kingdom
Website: bigwetfish.hosting


Brevo

Role: Email delivery services including transactional, notification, and marketing automation email delivery
Data processed: Name, email address, platform activity, and profile data required to deliver personalised and triggered communications
Location: European Union
Website: brevo.com


Legal responsibility for the content on this page sits with 3manfactory Ltd.

Platform Security Principles

Platform and organisational security is maintained through a combination of technical controls at the infrastructure level and organisational measures governing how staff operate.

Technical Controls

  • Data in transit is encrypted via TLS
  • Login credentials are protected using AES encryption
  • A software firewall is in place at the server level
  • Malware scanning runs continuously with automatic removal of known threats
  • Known bots are blocked at the network edge
  • Mod Security enterprise ruleset is applied for additional protection
  • Tenant isolation is enforced through Docker containerisation

Organisational Controls

  • All staff operate under a formal Information Security Policy
  • Strong 14-character passwords are required, managed via 1Password
  • Two-factor authentication is enabled across systems where available
  • All devices are auto-locked when unattended
  • Staff receive data protection and information security training at induction and at regular intervals
  • Cyber and data security insurance is maintained
  • A formal risk assessment process is maintained, with a risk register reviewed regularly

Legal responsibility for the content on this page sits with 3manfactory Ltd.