Security Policy

How WedgewoodAI protects your data across all our services and sub-domains.

Last updated: 1 October 2026

Operated by WedgewoodAI Tapui Limited (NZBN 9429053698575)

Scope

This Security Policy applies to wedgewoodai.com and the services and applications operated by WedgewoodAI Tapui Limited, including:

  • caddiechat.wedgewoodai.com — CaddieChat
  • aurashop.wedgewoodai.com — AuraShop
  • aurakinai.wedgewoodai.com — AuraKin AI
  • AuraBiz AI (under development)
  • wedgewoodaigolfclub.abacusai.app — WedgewoodAI Indoor Golf Club
  • Footprints & Folios — personal websites we build and host for customers

All services are hosted on infrastructure provided by Abacus.AI. Each product runs as its own application. Platform-level protections (HTTPS, managed hosting, patching) apply to every product; the website-specific measures described below apply to wedgewoodai.com, and we are bringing each product application up to the same standard.

Our Security Measures

Encryption in Transit

HSTS + TLS

All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. We enforce HTTP Strict Transport Security (HSTS) with a 1-year max-age, including all sub-domains, and are preload-ready.

Content Security Policy

CSP

wedgewoodai.com sends a Content Security Policy (CSP) that limits which outside sites can supply scripts, frames and connections, blocks plugins, and restricts where forms can submit. It reduces the risk of cross-site scripting (XSS). We are continuing to tighten it, including removing the remaining allowance for inline scripts.

Administrator Access

2FA + bcrypt

Administrative access requires email/password authentication with bcrypt-hashed passwords, plus mandatory Two-Factor Authentication (TOTP) compatible with Microsoft Authenticator, Google Authenticator, and other apps. Administrator sign-ins trigger an email alert.

Customer Account Protection

bcrypt + lockout

MyProducts passwords are never stored in readable form — they are hashed with bcrypt (cost factor 12). After five failed sign-in attempts an account is temporarily locked. Sign-in and registration forms are protected by Cloudflare Turnstile bot checks, and you can choose to sign in with Google instead of a password. Sign-in cookies cannot be read by page scripts and are only sent over HTTPS.

Input Validation & Sanitisation

XSS Prevention

All user inputs are sanitised to strip HTML tags, control characters, and potential injection payloads. Data is HTML-escaped before rendering. Email addresses, field lengths, and content types are strictly validated.

Rate Limiting & Brute Force Protection

Rate Limiting

Public forms and sign-in endpoints are rate-limited to slow down brute-force attacks and spam. Repeated failed attempts are logged and blocked for a period of time.

Security Headers

Defence in Depth

Pages on wedgewoodai.com are served with security headers: X-Content-Type-Options (nosniff), X-XSS-Protection, Referrer-Policy (strict-origin-when-cross-origin), Permissions-Policy (blocking camera, microphone, geolocation), Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy. The X-Powered-By header is removed.

Payments

Stripe

Card payments are handled by Stripe. Your full card number is entered directly with Stripe and is never stored on our systems. We keep only a record of what was bought and its payment status.

Bot & Spam Prevention

Our forms use several layers of protection against automated abuse:

  • Honeypot fields — Hidden form fields that trap bots attempting to fill in every input
  • Math CAPTCHA — A simple arithmetic challenge on the contact form that humans solve easily but blocks scripted submissions
  • Cloudflare Turnstile — Bot verification on MyProducts sign-in and registration
  • Content-Type enforcement — Requests must be valid JSON to be processed
  • Field length limits — Inputs are capped at reasonable lengths

Monitoring & Logging

We maintain comprehensive security logging across all services:

  • Access logging — All administrative actions, login attempts (successful and failed), and security events are logged with timestamps and IP addresses
  • Email alerts — Real-time notifications are sent to administrators on login, emergency shutdown events, and user management actions
  • Rate limit monitoring — Excessive requests are logged for review and blocked to protect service availability
  • Failed authentication tracking — Failed login attempts, invalid TOTP codes, and non-authorised email domains are all recorded

Cookies & Advertising

We keep tracking to a minimum:

  • No advertising — wedgewoodai.com does not show ads and does not load advertising scripts
  • Essential cookies only — We use only the cookies needed for sign-in, security checks and your display preferences
  • Transparent disclosure — Our Privacy Policy explains each type of cookie and its purpose

API Security

External API endpoints used by our applications are protected by:

  • API key authentication — All inter-service API calls require a valid API key in the request header
  • Input validation — Required fields are verified and data types are enforced
  • Application-level access control — Emergency shutdown capability allows instant access revocation per-application or globally

Infrastructure & Platform

Our services run on the Abacus.AI platform which provides:

  • Managed hosting with automatic security patches
  • Isolated application environments
  • Automated SSL/TLS certificate management
  • DDoS protection at the infrastructure level

Security Checklist

HTTPS/TLS encryption on all domains
HSTS with preload across all sub-domains
Content Security Policy (CSP)
X-Content-Type-Options: nosniff
XSS Protection headers
Referrer-Policy: strict-origin
Permissions-Policy (camera/mic/geo blocked)
Cross-Origin-Opener-Policy
Cross-Origin-Resource-Policy
X-Powered-By header removed
upgrade-insecure-requests enforced
bcrypt password hashing (cost 12)
Account lockout after repeated failed sign-ins
Two-Factor Authentication (TOTP) for administrators
JWT httpOnly/secure cookies
Admin domain restriction
Rate limiting on forms and sign-in
Input sanitisation & HTML escaping
Honeypot, CAPTCHA & Turnstile on forms
No full card numbers stored (Stripe)
API key authentication
Comprehensive access logging
Real-time email security alerts
Emergency app shutdown capability
No advertising or tracking cookies
Admin panel hidden from search engines
security.txt published for researchers

Reporting Security Vulnerabilities

We take security seriously. If you discover a vulnerability in any of our services, we ask that you disclose it responsibly:

How to report:

Email: [email protected]

Our contact details are also published in machine-readable form at /.well-known/security.txt.

Please include:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • The affected service or sub-domain
  • Your contact information for follow-up

Our commitment: We will acknowledge your report within 48 hours and provide an estimated timeline for resolution. We will not take legal action against security researchers who report vulnerabilities responsibly.

If a security incident affects your personal information, we will follow the breach-notification commitments set out in our Privacy Policy.

Security is a shared responsibility

While we implement comprehensive security measures, we encourage users to protect their accounts by using strong passwords and enabling Two-Factor Authentication when available.