Skip to content

Security

Verified website controls, stated without inflated claims

This page describes the controls that protect the Wait Wherever website and enquiry workflow, together with security requirements that vary by deployment.

Verified 30 August 2026

Security at a glance

Controls, operational practices, and clear boundaries

Security is easier to assess when current controls, deployment requirements, and product boundaries are clearly documented.

Implemented controls

Marketing website and enquiry controls

Schema, origin and size validation, abuse checks, escaped email output, and server-only delivery secrets.

Operational governance

Deployment-specific security review

Access, retention, monitoring, incident, hosting, and vendor controls are reviewed for each production environment.

Confirm for your deployment

Certification and regulated use

SOC 2, ISO, HIPAA, formal SLA, SSO, and audit-log requirements must be confirmed during procurement.

Scope note: Security and data-handling requirements vary by deployment. Contact us to review controls against your organization’s needs.
01

Marketing enquiry controls

These controls reduce common form abuse. They do not make a public endpoint immune to attack and should be monitored and strengthened as traffic grows.

  • Strict server-side schema validation
  • Request-size and origin validation
  • Honeypot and minimum-completion-time checks
  • Best-effort server rate limiting
  • Escaped HTML and plain-text email output
  • Generic public error responses
  • No intentional PII logging in application code
02

Data handling

The website sends validated enquiries through Resend to the configured business mailbox. It does not create its own enquiry database. Secrets are supplied through server-only environment variables and are not included in browser bundles.

03

Frontend safeguards

Important marketing content is server rendered. The site uses the Next.js App Router, dependency locking, accessible controls, and a limited third-party runtime surface. No advertising or analytics scripts are included.

04

Deployment-specific requirements

The following certifications and enterprise controls are not represented as included unless they are documented in your agreement.

  • SOC 2 and ISO certification scope
  • HIPAA or sector-specific compliance requirements
  • Formal service-level agreements
  • SSO and enterprise identity controls
  • Audit-log access and retention
05

Responsible reporting

If you believe you have found a security issue in this website, use the contact form and choose Security. Do not include sensitive personal data, active exploit material, or third-party secrets in an initial report.

Security and product fit

Review the workflow against your requirements

Share the controls, deployment constraints, and data-handling questions that matter to your team. We’ll map them to documented controls and identify any deployment-specific requirements.