Security and Privacy of your data
We take security and privacy of data extremely seriously. Below you will see a long list of the precautions we take to ensure that your data is both secure and private. However, it is important to remember that there are a few basic measures that you can take in your office to ensure security and without doing these first, the things that we do wouldn’t serve any useful purpose.
For instance, you need to remember:
- You are responsible for which staff you give access to.
- Ensure that you restrict access to Malinko where possible, do not give log in details to all staff without first thinking why they would need access.
- Do not share login details with anyone.
- Do not put your login details on a post-it note and stick it to your monitor.
- Choose secure passwords.
- Change password if you suspect your account has been compromised.
- Close accounts for staff who have left.
In return, this is our side of the bargain:
- All logins are password protected, we automatically generate high strength passwords, and once you have logged in you can change the password.
- There are different access levels for different users, so only some users can access the settings
- All connections are encrypted using https
- You are also able to download data and reports at any time in a format that can loaded in a spreadsheet.
- Data access for Liquid Bronze staff is restricted to the IP address of our office. There are three members of staff at Liquid Bronze and you are welcome to visit our offices at any time for auditing purposes.
- The data is stored within the UK in a secure data centre, with restricted physical access. This data centre has UPS and on site generator backups to prevent downtime in the event of a power cut. There is 24/7 monitoring on all aspects of the network and infrastructure. It has a redundant public network so if one line goes down there is another separate line to connect to the internet.
- Data recovery: we back up your data multiple times a day and these backups are stored offsite in another server to ensure that no data is lost. In the event of a complete catastrophe we would be able to get your data back – it would never be lost.
- We store the IP address of the most recent login on all our accounts.
- If required, we can restrict access to your account so only specific IP addresses can login. However, this would prevent mobile users from accessing the system other than via a VPN, and would prevent home users from accessing via a VPN unless they are on a static IP address, which is unusual for domestic internet connections.
- Data segregation: There are multiple checks within the code to ensure that data being requested is only accessible to the correct account.
- We follow industry best practices and react to security advisories as soon as we are aware of them. We are aware security is a continual process, rather than a single achievement.
- We can arrange an escrow service to ensure in the unlikely event that Liquid Bronze goes bust there is a separate organisation that holds a copy of all your data and a copy of the code that Malinko is written in. However, Liquid Bronze has been around for over 10 years – we are not a new company with a single activity.
We are happy to discuss any further concerns you may have about data security and privacy, so please do not hesitate to get in touch if you have any questions. Contact Us






