Security & Trust

How we protect your data

Performance West Ltd handles sensitive regulatory and client information. Security is built into how we operate — from the infrastructure up to every filing.

Independently verified

🔒

TLS A+ (Qualys SSL Labs)

Every connection uses modern, AEAD-only encryption (TLS 1.2/1.3). Verify →

🛡️

Security Headers A

HSTS (preloaded), CSP, X-Frame-Options and more. Verify →

GDPR · PCI · NIST compliant TLS

Encryption posture independently scanned and confirmed compliant with GDPR-aligned, PCI DSS, and NIST guidance.

🏢

SOC 2 Type II hosting

Our systems run in a SOC 2 Type II compliant data center with physical and operational controls.

💳

PCI-compliant payments (Stripe)

We never store card data. All payments are processed by Stripe (PCI DSS Level 1).

✉️

Email authentication

SPF, DKIM, DMARC, and MTA-STS protect against spoofing of our domain.

Our security practices

Encryption everywhere. All traffic to our website, client portal, and APIs is encrypted in transit with TLS 1.2/1.3. Sensitive data is encrypted at rest.

Least-data principle. We collect only the information needed to complete your filing, and we don't sell your data. For payments we never touch card numbers — Stripe handles them directly.

Hardened infrastructure. Our servers sit behind a default-deny firewall with only the necessary public services exposed, automatic security updates, intrusion monitoring, and isolated environments for each workload.

Access control. Administrative access is key-based and restricted; we follow least-privilege and review access regularly.

Report a security issue

We welcome responsible disclosure. If you believe you've found a vulnerability, please email security@performancewest.net. Our machine-readable policy is published at /.well-known/security.txt.

Note: Performance West Ltd provides compliance consulting services, not legal advice. See our Privacy Policy and Terms of Service.