TMGuard Security

Last updated 27 September 2026. Next review 19 July 2026.

TMGuard handles trade mark monitoring data for small businesses and IP professionals. This page describes how we protect that data: the controls we have in place, how we think about risk, and how to reach us with questions or vulnerability reports. It is updated when our practices change.

At a glance

Infrastructure

TMGuard runs on SOC 2 Type II certified hosting and database providers (Vercel, Cloudflare and Neon). The website’s server functions, the backend and the database run in London. Payment processing is handled by Stripe, a PCI-DSS Level 1 certified provider; we never store card data or handle it directly. Email delivery uses a GDPR-compliant transactional email provider.

Access to production infrastructure is restricted to authorised administrators with authentication controls appropriate to the sensitivity of the action.

Data protection

Data is encrypted in transit using modern TLS. Transport security is enforced by HTTP Strict Transport Security with a long-duration policy, which instructs browsers never to connect over plain HTTP.

Data is encrypted at rest using industry-standard algorithms at the storage layer.

Passwords, where used, are protected with modern cryptographic hashing rather than reversible encryption or plaintext storage.

Application security

Content Security Policy is enforced site-wide with an allowlist of permitted sources for scripts, styles, images, and connections.

User-visible content rendered from the database is sanitised before rendering, to prevent script injection.

Security headers are applied on every response: Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Framing of TMGuard pages is disallowed by default.

Public endpoints, including the free check, sign-in and sign-up, are rate limited.

Access and authentication

Session tokens are short-lived and rotated when account credentials change. Administrative sessions have tighter lifetimes than customer sessions.

Tenant data isolation is enforced at the database query layer. Every customer-scoped query is filtered by tenant identity derived from the authenticated session, never from client-supplied input.

Dependency hygiene

Dependencies are reviewed monthly. High-severity vulnerabilities in direct or transitive dependencies are patched within one week of disclosure where upstream fixes are available.

Libraries without upstream security fixes are replaced or contained through compensating controls.

Compliance and privacy

TMGuard is registered with the UK Information Commissioner’s Office as a data controller. We operate under the UK GDPR and associated data protection regulations.

A Data Processing Agreement is available to B2B customers on request via security@tmguard.uk. We maintain an Article 30 Record of Processing Activities, and have conducted Data Protection Impact Assessments and Legitimate Interest Assessments for the processing activities that require them. Summaries are available to customers on request.

Sub-processors assist with hosting, database, document storage, payments, email, analytics and AI processing. AI processing covers public trade mark register data and, when a customer uses them, the correspondence forwarded to TMGuard’s inbox and the questions asked of its assistant. The full list, including purposes and processing locations, is shared with B2B customers under DPA.

When a subscription ends, we keep the account's personal data for 30 days and then anonymise it: the sign-in address, forwarded correspondence, uploaded evidence and sign-in records are deleted, and the monitoring record (the marks watched and the matches found) is kept without anything that identifies you. For a subscription that ends on or after 27 October 2026, the period is 90 days. Account holders can also request deletion from their account page; deletion removes everything and runs 30 days after the request.

Customers may request data export or deletion at any time via privacy@tmguard.uk; requests are handled within statutory timeframes.

Incident response

TMGuard maintains an incident response procedure covering detection, containment, remediation, and notification.

If a personal data breach is likely to put people at risk, we notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and we tell affected customers without undue delay where the risk to them is high.

Material security incidents are logged; a public post-incident summary will be published where appropriate once remediation is complete.

Responsible disclosure

We welcome security research into TMGuard. Vulnerabilities should be reported privately to security@tmguard.uk.

A security.txt file is published at /.well-known/security.txt following RFC 9116.

Change history

26 September 2026

The response-time commitments for vulnerability reports were withdrawn pending confirmation. Statements that were no longer true were removed or corrected: the region (London, not the EU), an audit trail of administrative actions, which does not exist yet, a dependency audit at zero high-severity vulnerabilities, database-layer tenant isolation, per-tenant rate limits, the retention period, the breach notification timeframe and the scope of AI processing. Later the same day, the retention statement was corrected again: the anonymisation it described does not run. A full revision of this page follows.

19 April 2026

Security page first published. Full internal security audit completed with all critical and high findings closed. Session handling hardened. Content Security Policy moved to enforce mode. Tier-aware rate limiting shipped. Dependency audit reduced to zero high-severity vulnerabilities. Security headers enforced site-wide.

Security: security@tmguard.uk
Privacy: privacy@tmguard.uk
Other: hello@tmguard.uk
TMGUARD LTD, Company No. 17055456, tmguard.uk. Privacy policy · Terms