Journl

Security

Version 1 · effective from [date]

Journl holds other businesses' financial records. This page says how we look after them, and how to tell us if you think something is wrong.

Reporting a security concern

If you believe you have found a vulnerability in Journl, or that an account or data has been accessed without permission, email security@journl.co.uk. It is read by the people who build the software, not a ticket queue.

If there is a breach

If we discover that personal or customer data has been exposed, lost, or accessed without authority, we follow a written procedure:

  1. Contain it. Revoke the affected credentials or sessions, close the route in, and preserve the logs.
  2. Establish what happened: which data, which customers, since when.
  3. Tell the people affected within 72 hours of becoming aware, with what we know, what we have done, and what they should do.
  4. Tell the Information Commissioner's Office within 72 hours where personal data is involved, as UK GDPR requires.
  5. Tell HM Revenue & Customs within 72 hours where the breach concerns data handled through Making Tax Digital, by logging a ticket on the HMRC Developer Hub with a named contact and telephone number.
  6. Fix the cause, and write down what we learned.

How your data is protected

What we ask of you