Trust center

What we actually do to protect your data.

This page lists the security and privacy controls behind this website and behind WML Command, our client platform.

Everything below can be checked: response headers, provider documentation, or a document we will send you on request.

We are a small team, not a certified enterprise vendor. Where a control does not exist yet, this page says so instead of implying otherwise.

Page last reviewed:

At a glance

Transport encryption
HTTPS everywhere, HSTS with preload
Encryption at rest
AES-256 on managed provider storage
Data location
United States
Account protection
Individual accounts, roles and 2FA
Reported incidents
None to date
External audit
Not yet commissioned

Controls in place

How this site is served

Every page and form travels over HTTPS.

The site sends a strict transport policy so browsers refuse an unencrypted connection for two years, even if someone types the address without the s.

  • Strict-Transport-Security with a two-year window, subdomains included and preload requested.
  • A Content-Security-Policy that names every external host allowed to run a script, load an image or open a connection.
  • X-Frame-Options DENY and frame-ancestors none, so the site cannot be embedded to trick a visitor into clicking something.
  • X-Content-Type-Options, Referrer-Policy, Permissions-Policy and Cross-Origin-Opener-Policy on every response.

You can confirm all of this yourself: open your browser's network tab on any page and read the response headers.

Encryption

In transit, traffic is protected by TLS between your browser and our infrastructure, and between our infrastructure and every provider we call.

  • In transit: TLS on every connection, with HTTP downgraded automatically.
  • At rest: our hosting (Vercel) and our database and file storage (Supabase) encrypt stored data with AES-256 on managed volumes.
  • Backups inherit the same encryption as the storage they come from.
  • Secrets and API keys live in the platform's encrypted environment configuration, never in the code repository.

Where your data lives

We do not spread client data across regions. Everything sits with a small, named set of providers in the United States.

  • Website and application hosting: Vercel, United States.
  • Database, authentication and file storage: Supabase, United States.
  • Transactional email: Resend, United States.
  • Analytics, only after you consent: Google Analytics 4 and Microsoft Clarity (United States) and Ahrefs Web Analytics (Singapore, cookieless).

If your organisation needs data kept in a specific country, tell us before we start: for some projects we can deploy to a different region.

Who can reach client data

Access is personal and limited. Nobody uses a shared login, and nobody keeps access they no longer need for their work.

  • Individual named accounts. Shared credentials are not used for any system that holds client data.
  • Role-based permissions in WML Command: owner, administrator and member, each with a different reach.
  • Two-factor authentication with an authenticator app, required to sign in.
  • Sessions can be revoked remotely, and access is removed the same day someone stops working on an account.
  • Client credentials we are given for hosting, domains or ad accounts are stored in a password manager, never in email or chat.

How we build and operate

Security is part of the build, not a review at the end.

  • Public forms are rate-limited per IP address and per email address to blunt abuse and spam.
  • Form input is length-checked and escaped before it reaches an email template or the CRM.
  • Dependencies are updated regularly, and the build fails on lint errors rather than shipping them.
  • Production and development are separate environments with separate credentials.

Certifications and compliance

We hold no security certification of our own.

We are not SOC 2 audited, not ISO 27001 certified, and we do not offer a HIPAA business associate agreement.

Saying so plainly matters more to us than a badge nobody can verify.

What we can offer is the list of controls above, the providers behind them, and a signed confidentiality agreement for your project.

What we can demonstrate

  • A written confidentiality clause in every proposal, and a separate NDA on request.
  • A data processing description we can send to your legal or IT team.
  • Infrastructure providers that do hold SOC 2 Type II and ISO 27001 (Vercel, Supabase, Google, Microsoft), whose reports are public.
  • No card data ever touches our systems: payments run through certified gateways such as Stripe and PayPal.

What we do not have yet

  • SOC 2 Type II report for World Marketing Labs.
  • ISO 27001 certification.
  • HIPAA business associate agreement.
  • Third-party penetration test report.

Audits and testing

We have not commissioned an independent penetration test yet. When we do, this page will say who performed it and when.

What runs today is continuous rather than ceremonial: automated dependency updates, an automated test suite on the sensitive server code, and header and configuration checks before every deployment.

If a project of yours requires an independent test, we can scope one with a specialised firm and include it in the proposal.

Incident history

No security incident affecting client data has occurred since this platform went live in July 2026.

If one ever does, it will be published here with the date, what was affected, what we did and what changed afterwards, whether or not the law requires the notice.

We commit to notifying affected clients directly within 72 hours of confirming an incident that involves their data.

No incidents recorded.

Reporting a vulnerability

If you have found a security problem in this website or in WML Command, we want to hear about it before anyone else does.

Write to the address below with enough detail to reproduce the issue.

You do not need a formal report, a clear description and the steps you took are enough.

contact@worldmarketinglabs.com
  1. 1

    We acknowledge

    Within 3 business days of your email, so you know a human read it.

  2. 2

    We triage

    Within 10 business days we tell you whether we could reproduce it and how seriously we rate it.

  3. 3

    We fix

    Critical issues are patched as fast as we can build and verify a fix; everything else gets a target date we share with you.

  4. 4

    We credit you

    If you want the credit, we name you here once the fix is live. We do not run a paid bug bounty.

What we ask

  • Give us reasonable time to fix the issue before making it public.
  • Use only accounts and data that belong to you; do not access, modify or delete anyone else's.
  • No denial-of-service, spam, social engineering or physical attacks against our team or providers.
  • Stop as soon as you have confirmed a vulnerability exists, there is no need to prove how far it goes.

If you follow these rules, we will treat your research as authorised, we will not pursue legal action, and we will work with you until the issue is resolved.

Questions about any of this?

Security questionnaires, vendor reviews and IT-team questions are welcome. Write to us and a person who knows the answer will reply.