logo

Policies > Security overview

Last updated: 1 August 2026

JustPost applies technical and organisational measures designed to protect the confidentiality, integrity and availability of customer data. Our security controls are reviewed regularly and are proportionate to the nature of the services we provide.

A. Introduction

JustPost is a platform operated by FairSay Ltd that enables organisations to create and manage campaigns involving the distribution of printed communications, including postcards and other supporter engagement activities.

We recognise that campaigns supported through the JustPost platform may involve information relating to individuals' political opinions, affiliations, activism, or engagement with campaigns. Such information may constitute sensitive or special category personal data under applicable data protection laws.

FairSay Ltd is registered with the UK Information Commissioner's Office (ICO) as an organisation that processes politically sensitive personal data. We apply appropriate technical and organisational measures designed to protect the confidentiality, integrity and availability of information processed through the JustPost platform.

This Security Policy describes the measures implemented to protect customer data and support the secure operation of the JustPost platform.

B. Security principles and governance

Security is integrated into the design, development and operation of the JustPost platform.

Our approach is based on the following principles:

  • Confidentiality — ensuring that customer data is accessible only to authorised individuals and systems.
  • Integrity — protecting information from unauthorised modification or loss.
  • Availability — designing services to remain reliable and recoverable.

We apply security measures appropriate to the nature of the information processed, including supporter engagement data and campaign-related information.

Security responsibilities are managed within FairSay Ltd, with access to systems limited to authorised personnel and approved developers or subcontractors who require access to perform their duties.

C. Infrastructure and hosting

JustPost is hosted using managed cloud infrastructure designed to provide secure, reliable and scalable services.

Our infrastructure includes:

  • Managed cloud hosting services.
  • EU-based data hosting where applicable.
  • Managed database services.
  • Secure object storage for uploaded files and generated content.
  • Content delivery services where required.

Infrastructure providers are selected based on their reliability, security practices and ability to support appropriate data protection requirements.

JustPost is designed to operate using managed services where appropriate, reducing operational risk and allowing security updates and infrastructure maintenance to be handled by specialist providers.

D. Access control

Access to JustPost systems is restricted to authorised users based on their role and operational requirements.

Our access control practices include:

  • Least-privilege access principles.
  • Individual user accounts rather than shared accounts.
  • Multi-factor authentication (MFA) for administrative accounts.
  • Restricting production access to authorised FairSay personnel, developers and approved subcontractors who require access.
  • Removal of access when it is no longer required.

Customer dashboard access is controlled by customer administrators, who are responsible for managing users within their organisation.

Secrets and sensitive configuration

Sensitive application configuration, including credentials, API keys and other secret values required by the JustPost platform, is managed using controlled secret-management facilities provided by the platform infrastructure. Secrets are not intentionally stored in application source code or publicly accessible configuration. Access to sensitive configuration is restricted to authorised personnel and systems according to operational requirements.

E. Encryption

Encryption is used to help protect information during storage and transmission.

Measures include:

  • Encryption of data in transit using secure communication protocols.
  • Data encrypted at rest by our managed database provider.
  • Secure handling of application credentials and secrets.

F. Data protection and privacy

JustPost is designed to support customers in meeting their data protection obligations.

Customers generally act as data controllers for information submitted to the JustPost platform, while FairSay Ltd acts as a data processor providing the platform services.

Measures include:

  • Logical separation of customer data between organisations.
  • Restricting access to customer information to authorised systems and personnel.
  • Data minimisation principles.
  • Defined data retention practices.
  • Secure deletion processes where applicable.
  • Support for customer requests relating to their data protection obligations.

Customers are responsible for ensuring that they have an appropriate lawful basis for processing personal data through JustPost, including where campaigns involve special category personal data such as political opinions.

Customer administrators are also responsible for ensuring that exported or downloaded data is handled securely and in accordance with applicable data protection requirements.

Further information about privacy and personal data processing is available in the JustPost Privacy Policy.

G. Secure software development

Security is considered throughout the development lifecycle of JustPost.

Our development practices include:

  • Source-controlled software development.
  • Manual code review.
  • Automated testing.
  • Regular software updates.
  • Updating dependencies and applying security-related fixes where appropriate.
  • Secure handling of application credentials and secrets.

Development and production environments are separated to reduce the risk of unintended changes affecting customer data.

H. Monitoring, logging and incident response

JustPost uses logging and monitoring capabilities to support operational reliability, troubleshooting and security investigations.

Relevant logs are maintained by:

  • Managed infrastructure providers where applicable.
  • JustPost application infrastructure, including systems used to support authorised dashboard activity.

Activities such as moderation, campaign setup, reporting and authorised supporter data access are performed through controlled systems that maintain relevant operational records.

If a security incident occurs, we will investigate the issue, take appropriate corrective action, and notify affected customers where required by applicable data protection laws.

Where required by applicable data protection laws, customers will be notified of personal data breaches without undue delay.

I. Personnel security

Access to JustPost systems is limited to authorised individuals who require access to perform their responsibilities.

Personnel and contractors with access to systems are expected to:

  • Maintain confidentiality of customer information.
  • Follow appropriate security practices.
  • Protect authentication credentials.
  • Only access information necessary for their role.

J. Physical security

Physical security of data centres and core infrastructure is managed by our cloud infrastructure providers.

JustPost relies on providers that implement physical security measures designed to protect hosted systems and customer data.

K. Third-party processors and subprocessors

JustPost uses selected third-party service providers to deliver parts of the platform infrastructure and related services.

Third-party providers are selected based on factors including security practices, reliability, contractual commitments and data protection requirements.

Current subprocessors include (Provider -> Purpose -> Data location):

  • Supabase -> Managed database hosting -> European Union
  • Vercel -> Application hosting -> European Union
  • Krystal Hosting & Amazon Web Services (AWS) -> Backend server -> European Union
  • Amazon Web Services (AWS) and Cloudinary -> CDN -> European Union
  • Mailjet and Brevo -> Transactional email delivery -> European Union
  • Locize -> Internationalisation and Localisation (no client content) -> European Union/Switzerland
  • Github -> Private code repositories (no client data) -> USA
  • Print providers -> various depending on delivery address
  • Postal operator -> various depending on delivery address

Subprocessors are subject to appropriate contractual arrangements, including data processing agreements where required.

L. Supplier security assurance

FairSay relies on carefully selected third-party providers for infrastructure, hosting, communications, storage and other operational services that support the JustPost platform.

As part of supplier assessment and ongoing review, FairSay considers factors including security practices, data protection commitments, operational resilience, contractual protections, independent assurance reports and recognised security certifications where relevant.

Where suppliers maintain recognised security certifications or assurance frameworks, these may include standards such as ISO/IEC 27001, SOC 2 or equivalent industry frameworks.

Supplier certifications and assurance measures are considered alongside the nature of the service provided, the type of data processed and the overall risk associated with the service.

Key supplier security certifications

The following suppliers used by JustPost maintain publicly available security information and certifications where applicable:

  1. Supabase (database hosting): ISO 27001 announcement
  2. Vercel (application hosting): ISO 27001 & compliance information
  3. AWS (API, CDN and dashboard hosting): ISO 27001 FAQs

For suppliers that process customer personal data on behalf of FairSay, see the JustPost Subprocessor List.

M. Business continuity and backups

JustPost is designed for resilience and continuity.

Measures include:

  • Automated backups of customer data.
  • Recovery procedures that are reviewed periodically.
  • Use of managed infrastructure services designed to support availability and recovery.

We design our services for resilience and continuity while recognising that no online service can guarantee uninterrupted availability.

N. Vulnerability management and responsible disclosure

Security vulnerabilities are taken seriously.

Our approach includes:

  • Regular software updates.
  • Reviewing security-related updates and dependency changes.
  • Addressing identified security issues appropriately based on their severity and impact.

If you believe you have identified a security vulnerability affecting JustPost, please report it responsibly by contacting: support@justpost.pro

Please include sufficient information to help us understand and investigate the issue.

We request that security researchers avoid accessing, modifying or deleting customer data and provide reasonable time for investigation and remediation before publicly disclosing vulnerabilities.

O. Compliance and regulatory commitments

JustPost is designed to support customers in meeting applicable data protection obligations.

Our approach includes:

  • Compliance with applicable UK GDPR and EU GDPR requirements.
  • Maintaining appropriate contractual arrangements with customers and subprocessors.
  • Supporting customers through appropriate data processing documentation.

FairSay Ltd maintains registration with the UK Information Commissioner's Office (ICO) for relevant data processing activities.

Our infrastructure providers maintain their own security certifications and compliance programmes where applicable. These certifications apply to their services and do not represent certification of JustPost itself unless explicitly stated.

P. Customer responsibilities

Security is a shared responsibility between JustPost and its customers.

Customers are responsible for:

  • Ensuring appropriate user access permissions within their organisation.
  • Not sharing user login credentials between individuals.
  • Using strong passwords.
  • Using MFA on JustPost dashboard accounts (MFA is required for customer dashboard accounts).
  • Keeping devices, operating systems and browsers updated.
  • Ensuring exported or downloaded data is handled securely.
  • Ensuring campaigns and data processing activities comply with applicable laws and regulations.

Customers should promptly report suspected security issues or unauthorised access.

Q. Service reliability and business continuity

FairSay maintains documented processes to support service reliability, operational resilience and recovery following disruption.

Further information on service availability, continuity planning and recovery arrangements is provided in the Service Reliability Statement and Business Continuity & Disaster Recovery Procedure.

R. Security contact

For questions about this Security Policy or to report security concerns email: support@justpost.pro

Document review

This Security Policy is reviewed periodically and may be updated to reflect changes to the JustPost platform, security practices or applicable requirements.

Revision history

  • 27 July 2026: Initial publication (separated out from previously published policies)

Related documents

This overview should be read alongside our full policies, statements and commitments.

Values & commitments

Trust, transparency & assurance

Together, these documents explain how JustPost operates, how we protect information and the standards expected of organisations using the platform.