Security practices
Data Protection
How WebCastle collects, stores, encrypts, separates and retains customer data across development, hosting and support work, and how that data is deleted.
At a glance
- Customer data is processed only to deliver contracted services.
- TLS in transit; cloud provider managed encryption at rest.
- Client environments and data are kept logically separate.
- Classification, retention and disposal procedures are being formalised.
Overview
WebCastle builds, deploys and supports web and mobile applications for its clients. In most engagements WebCastle is a processor acting on the instructions of the client, who determines what data is collected and why. WebCastle holds customer data because delivering, hosting and supporting those systems requires it — not for any independent purpose.
The baseline is consistent across engagements: transport is encrypted, storage in WebCastle-operated cloud environments uses cloud provider managed encryption, each client is kept logically separate from every other client, and access to production data is limited to the technical personnel working on that engagement.
Above that baseline, several practices are being formalised. Classification, retention schedules and disposal procedures exist as working practice today but are not yet written down and approved. This page states which is which so that a security reviewer can rely on it.
How WebCastle classifies data
A four-tier scheme is being adopted so handling rules follow sensitivity rather than project convention.
Public
Information already published or intended for publication, including marketing content and public documentation. No handling restrictions beyond integrity.
Internal
WebCastle operational information such as project plans, estimates and internal notes. Shared inside the company on a need-to-know basis and not disclosed externally.
Confidential
Client business information, source code, architecture detail and credentials-adjacent configuration. Access limited to the assigned delivery team and covered by contractual confidentiality.
Personal data
Data relating to identified or identifiable individuals held inside client applications. Handled under the client instructions and the applicable data protection terms, with the tightest access restrictions.
Data protection controls
Each control shows its current maturity. Items marked in-progress or developing describe practice that exists but is not yet documented and approved.
Encryption in transit
EstablishedData moving between customers, end users and WebCastle-managed services travels over TLS. Public endpoints delivered by WebCastle are served over HTTPS.
- Applications and administrative interfaces operated by WebCastle are configured to use HTTPS.
- Connections to cloud provider consoles and APIs use the provider encrypted endpoints.
- Where WebCastle inherits an environment built by a third party, transport configuration is reviewed during handover.
Encryption at rest
EstablishedStorage volumes, object storage and managed databases in WebCastle-operated cloud environments use cloud provider managed encryption at rest.
- Encryption is provided by the cloud platform using provider-managed keys.
- Backups produced by managed database services inherit the same provider-managed encryption.
Customer data segregation
EstablishedEach client engagement is kept logically separate. Environments, storage, databases and repositories are not shared between clients.
- Client workloads run in separate cloud accounts, projects or logically isolated environments rather than a shared multi-tenant estate.
- Source code repositories and issue trackers are scoped per client.
- Older environments inherited from previous providers are migrated to this model as they are brought under WebCastle management.
Restricted access to production data
EstablishedAccess to production systems and customer data is limited to a small number of technical personnel who need it to deliver the contracted work.
- Cloud provider consoles and critical administrative services require multi-factor authentication.
- Access is granted per engagement rather than across the whole client portfolio.
- Access is removed when personnel leave a project or the company.
Purpose limitation
EstablishedCustomer data is processed only to deliver the services set out in the contract. WebCastle does not sell customer data or use it to train third-party models.
- Processing activity is limited to development, deployment, support and troubleshooting of the contracted systems.
- Any new processing purpose is raised with the customer before it begins.
Data classification scheme
OperatingA written classification scheme is being introduced so that handling rules follow the sensitivity of the data rather than the habits of an individual project team.
- Draft tiers cover public, internal, confidential and personal data.
- Handling rules for each tier are being drafted alongside the scheme.
Data inventory and mapping
In practiceWebCastle is building a consolidated record of what customer data each engagement holds, where it is stored and which third parties are involved.
- Project-level knowledge exists today and is captured during onboarding and architecture discussions.
- Consolidating that knowledge into a single maintained inventory is under way.
Retention schedules
OperatingRetention is currently driven by contract terms and the configuration of each application. Standard retention schedules that apply across engagements are being defined.
- Where a customer specifies retention terms in the contract, those terms govern.
- Application-level retention is set during design and reviewed with the customer.
Deletion and disposal
OperatingCustomer data is deleted on request and at the end of an engagement. A documented, repeatable disposal procedure with written confirmation to the customer is being completed.
- Deletion covers production data stores, non-production copies and WebCastle-held working artefacts.
- Residual copies may persist in cloud provider managed backups until those backups age out under provider retention.
- WebCastle does not currently offer certified third-party destruction services.
Handling of data in non-production environments
In practiceDevelopment and staging environments are separated from production. Standard rules on the use of production data for testing are being tightened.
- Preference is for synthetic or anonymised data in development and staging.
- Where a production copy is genuinely required for a defect investigation, access follows the same restrictions as production.
Encryption key management
Under EvaluationWebCastle relies on cloud provider managed keys today. A formal key management standard, including customer-managed key options, is being assessed.
- Customer requirements for dedicated or customer-managed keys are handled case by case at design time.
Data loss prevention
Under EvaluationAutomated data loss prevention tooling is not in place. WebCastle is assessing whether endpoint and collaboration-suite controls are proportionate to its delivery model.
- Current mitigation is administrative: restricted access, per-client separation and contractual confidentiality obligations.
What WebCastle holds and why
Categories of data typically involved in an engagement. The specifics of any one project are defined in its contract and design documentation.
| Category | Why WebCastle holds it | What governs how long it is kept |
|---|---|---|
| Client application data | Required to build, host, migrate and support the application under contract. | The customer contract and the retention configured in the application itself. |
| End-user personal data | Present inside client applications that WebCastle develops or operates on the client behalf. | The client instructions as controller, and applicable data protection terms. |
| Source code and configuration | The deliverable itself, plus the configuration needed to run it. | Retained for the life of the engagement and the agreed support period. |
| Operational logs | Troubleshooting, defect investigation and service availability. | Cloud provider and application log settings for the environment. |
| Commercial and contact data | Managing the commercial relationship, billing and support contact. | Statutory record-keeping obligations and the customer contract. |
WebCastle does not publish fixed retention periods on this page. Retention applying to a specific engagement is set out in that customer agreement.
Data lifecycle in practice
- Collection
- WebCastle does not decide what an application collects. Collection is designed with the client, and WebCastle raises data minimisation during design review where a field or integration is not needed.
- Storage location
- Customer data is stored in the cloud region agreed for the engagement. Where a client requires a specific region for residency reasons, that requirement is set at design time and honoured for the life of the engagement.
- Backups
- Managed databases use cloud provider native backup capabilities. Backup copies inherit the encryption and access controls of the environment they belong to. Backup retention follows the provider configuration for that environment rather than a published WebCastle-wide schedule.
- Export
- Customers can request an export of their data in a standard machine-readable format. Exports are delivered over an authenticated channel agreed with the customer contact, and are handled as a defined request rather than a self-service feature.
- Deletion
- On written request, or at the end of an engagement, WebCastle deletes customer data from production and non-production environments under its control. Copies held in cloud provider managed backups expire under the provider retention for that environment.
Sub-processing and third parties
WebCastle uses a limited set of third-party providers to deliver its services. AWS is a primary cloud infrastructure provider. Other providers support source control, communication, ticketing and, in some engagements, client-selected services such as payment or messaging platforms.
Third parties involved in an engagement are agreed with the client during design. Client-selected services are integrated on the client instruction and remain under the client relationship with that vendor. A current list of the providers that may process customer data is maintained on the subprocessors page, and how WebCastle handles personal data more broadly is described in the privacy notice.
Notification of changes to the subprocessor list is handled through the customer agreement. Where a contract requires advance notice of a new subprocessor, that term governs.
What customers can request
Requests are made through the customer account contact or the security mailbox. Response times are good-faith targets and are not contractual service levels.
An export of your data
A machine-readable extract of the data held in your environment, delivered over an agreed authenticated channel.
Deletion of your data
Removal of your data from environments under WebCastle control at the end of an engagement or on written request, with confirmation once complete.
A list of who has access
The WebCastle personnel with access to your production environment, and the basis for that access.
Details of third parties involved
The providers processing data in your engagement, what they process, and the region in which they operate.
Assistance with data subject requests
Support in locating, exporting or deleting an individual record where you are responding to a request from one of your users.
Related
- SubprocessorsThe third-party providers that may process customer data, what they handle and where they operate.
- InfrastructureThe cloud environments where customer data is stored, and how they are configured and separated.
- Business continuityBackup strategy, recovery planning and how WebCastle restores service after a disruption.