Sections
Security Policy
Last updated: 21 August 2026
1. Introduction
Dafydd Thomas Software Ltd trading as sgwrs.cymru is committed to protecting our users' data. This policy outlines our approach to security, how to report vulnerabilities, and the practices we employ to keep your data safe.
2. Responsible Disclosure
If you believe you have discovered a security vulnerability in sgwrs.cymru, please contact us at security@sgwrs.cymru before any public disclosure.
Your report should include:
- A clear description of the vulnerability and its potential impact
- Detailed steps to reproduce the issue
- An impact assessment — which data or systems could be at risk
- Your contact details (optional, but allows us to acknowledge your contribution)
We will acknowledge your report within one business day. Where a vulnerability is confirmed, we offer public credit (if desired). We will not take legal action against security researchers who act in good faith and comply with this policy, provided that they:
- Do not access, modify or delete data belonging to other users
- Limit testing to the minimum necessary to demonstrate the vulnerability
- Do not degrade the availability of the Service for other users
We ask that you refrain from public disclosure until we have had a reasonable opportunity to respond.
3. Security Practices
We employ a range of measures to protect the service and your data:
- TLS encryption for all data transmitted between your device and our servers
- Clerk manages user authentication, with support for OAuth and MFA
- Convex as our database platform, with built-in infrastructure security controls
- Appropriate access controls to restrict who can access production data
- Regular security updates to platform dependencies and our own code
4. Data Storage
Chat messages are stored on Convex servers. All data transmitted between your browser and the service is encrypted over TLS. We do not store passwords — authentication is managed entirely by Clerk.
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify affected users without undue delay, in accordance with UK GDPR Article 34. We will report qualifying data breaches to the Information Commissioner's Office within 72 hours, as required by UK GDPR Article 33.
5. User Responsibilities
To keep your account secure, we recommend:
- Securing your OAuth provider accounts (Google, GitHub, etc.) with a strong password and 2FA where available
- Not sharing login sessions or session URLs with others
- Reporting any suspicious activity on your account to security@sgwrs.cymru immediately
6. Updates
Last updated: 21 August 2026
2026-08-21