Security
Verified website controls, stated without inflated claims
This page describes the controls that protect the Wait Wherever website and enquiry workflow, together with security requirements that vary by deployment.
Verified 30 August 2026
Security at a glance
Controls, operational practices, and clear boundaries
Security is easier to assess when current controls, deployment requirements, and product boundaries are clearly documented.
Implemented controls
Marketing website and enquiry controls
Schema, origin and size validation, abuse checks, escaped email output, and server-only delivery secrets.
Operational governance
Deployment-specific security review
Access, retention, monitoring, incident, hosting, and vendor controls are reviewed for each production environment.
Confirm for your deployment
Certification and regulated use
SOC 2, ISO, HIPAA, formal SLA, SSO, and audit-log requirements must be confirmed during procurement.
Marketing enquiry controls
These controls reduce common form abuse. They do not make a public endpoint immune to attack and should be monitored and strengthened as traffic grows.
- Strict server-side schema validation
- Request-size and origin validation
- Honeypot and minimum-completion-time checks
- Best-effort server rate limiting
- Escaped HTML and plain-text email output
- Generic public error responses
- No intentional PII logging in application code
Data handling
The website sends validated enquiries through Resend to the configured business mailbox. It does not create its own enquiry database. Secrets are supplied through server-only environment variables and are not included in browser bundles.
Frontend safeguards
Important marketing content is server rendered. The site uses the Next.js App Router, dependency locking, accessible controls, and a limited third-party runtime surface. No advertising or analytics scripts are included.
Deployment-specific requirements
The following certifications and enterprise controls are not represented as included unless they are documented in your agreement.
- SOC 2 and ISO certification scope
- HIPAA or sector-specific compliance requirements
- Formal service-level agreements
- SSO and enterprise identity controls
- Audit-log access and retention
Responsible reporting
If you believe you have found a security issue in this website, use the contact form and choose Security. Do not include sensitive personal data, active exploit material, or third-party secrets in an initial report.
Security and product fit
Review the workflow against your requirements
Share the controls, deployment constraints, and data-handling questions that matter to your team. We’ll map them to documented controls and identify any deployment-specific requirements.