Last updated 22 July 2026
1. Our approach
FOCUS is built on first-party data custody: registrations and applications happen natively on our own platform, not through third-party event tools, so we can hold data to a consistent standard. Security is designed in, not bolted on. This page describes the measures we take; because no system is ever perfectly secure, we treat security as an ongoing commitment rather than a finished state.
2. Protecting data in transit and at rest
- Encryption in transit. Traffic to and from the site is served over HTTPS/TLS.
- Encryption at rest. Stored data is protected on encrypted infrastructure.
- Segregated storage. Member records and uploaded media are held in our own database and object storage, not scattered across third-party platforms.
3. Access controls
- Access to personal data is limited to those who need it to run the network, on a least-privilege basis.
- Administrative access is protected and kept to a minimum, and credentials are managed through secure secret handling rather than shared files.
- We fail closed: if an authentication, database, or storage dependency is unavailable, the platform stops rather than degrading into an insecure state.
4. Protecting public intake
Every public form (registrations and applications) is protected by anti-bot measures to keep out automated abuse and preserve the quality and integrity of the data in the network. We collect only what we need and validate submissions before they enter our systems.
5. Hosting
The application and its database run on infrastructure currently located in the United States. This is a declared international transfer, protected by appropriate safeguards under UK GDPR. Uploaded profile media is stored separately, on servers in the European Union. See our Privacy Policy and Data Processing page for detail.
6. Breach response
We monitor for security events and maintain a process to respond to incidents. Where a personal data breach is likely to result in a risk to people's rights, we will notify the Information Commissioner's Office (ICO) without undue delay and, where required, within 72 hours, and we will inform affected people where the law requires it.
7. Reporting a concern
If you believe you have found a security issue affecting FOCUS, please tell us promptly and privately at [email protected] so we can investigate. We appreciate responsible disclosure and ask that you give us a reasonable chance to address an issue before sharing it publicly.