Security Policy
How WedgewoodAI protects your data across all our services and sub-domains.
Last updated: 1 October 2026
Operated by WedgewoodAI Tapui Limited (NZBN 9429053698575)
Scope
This Security Policy applies to wedgewoodai.com and the services and applications operated by WedgewoodAI Tapui Limited, including:
- caddiechat.wedgewoodai.com — CaddieChat
- aurashop.wedgewoodai.com — AuraShop
- aurakinai.wedgewoodai.com — AuraKin AI
- AuraBiz AI (under development)
- wedgewoodaigolfclub.abacusai.app — WedgewoodAI Indoor Golf Club
- Footprints & Folios — personal websites we build and host for customers
All services are hosted on infrastructure provided by Abacus.AI. Each product runs as its own application. Platform-level protections (HTTPS, managed hosting, patching) apply to every product; the website-specific measures described below apply to wedgewoodai.com, and we are bringing each product application up to the same standard.
Our Security Measures
Encryption in Transit
HSTS + TLSAll data transmitted between your browser and our servers is encrypted using HTTPS/TLS. We enforce HTTP Strict Transport Security (HSTS) with a 1-year max-age, including all sub-domains, and are preload-ready.
Content Security Policy
CSPwedgewoodai.com sends a Content Security Policy (CSP) that limits which outside sites can supply scripts, frames and connections, blocks plugins, and restricts where forms can submit. It reduces the risk of cross-site scripting (XSS). We are continuing to tighten it, including removing the remaining allowance for inline scripts.
Administrator Access
2FA + bcryptAdministrative access requires email/password authentication with bcrypt-hashed passwords, plus mandatory Two-Factor Authentication (TOTP) compatible with Microsoft Authenticator, Google Authenticator, and other apps. Administrator sign-ins trigger an email alert.
Customer Account Protection
bcrypt + lockoutMyProducts passwords are never stored in readable form — they are hashed with bcrypt (cost factor 12). After five failed sign-in attempts an account is temporarily locked. Sign-in and registration forms are protected by Cloudflare Turnstile bot checks, and you can choose to sign in with Google instead of a password. Sign-in cookies cannot be read by page scripts and are only sent over HTTPS.
Input Validation & Sanitisation
XSS PreventionAll user inputs are sanitised to strip HTML tags, control characters, and potential injection payloads. Data is HTML-escaped before rendering. Email addresses, field lengths, and content types are strictly validated.
Rate Limiting & Brute Force Protection
Rate LimitingPublic forms and sign-in endpoints are rate-limited to slow down brute-force attacks and spam. Repeated failed attempts are logged and blocked for a period of time.
Security Headers
Defence in DepthPages on wedgewoodai.com are served with security headers: X-Content-Type-Options (nosniff), X-XSS-Protection, Referrer-Policy (strict-origin-when-cross-origin), Permissions-Policy (blocking camera, microphone, geolocation), Cross-Origin-Opener-Policy, and Cross-Origin-Resource-Policy. The X-Powered-By header is removed.
Payments
StripeCard payments are handled by Stripe. Your full card number is entered directly with Stripe and is never stored on our systems. We keep only a record of what was bought and its payment status.
Bot & Spam Prevention
Our forms use several layers of protection against automated abuse:
- Honeypot fields — Hidden form fields that trap bots attempting to fill in every input
- Math CAPTCHA — A simple arithmetic challenge on the contact form that humans solve easily but blocks scripted submissions
- Cloudflare Turnstile — Bot verification on MyProducts sign-in and registration
- Content-Type enforcement — Requests must be valid JSON to be processed
- Field length limits — Inputs are capped at reasonable lengths
Monitoring & Logging
We maintain comprehensive security logging across all services:
- Access logging — All administrative actions, login attempts (successful and failed), and security events are logged with timestamps and IP addresses
- Email alerts — Real-time notifications are sent to administrators on login, emergency shutdown events, and user management actions
- Rate limit monitoring — Excessive requests are logged for review and blocked to protect service availability
- Failed authentication tracking — Failed login attempts, invalid TOTP codes, and non-authorised email domains are all recorded
Cookies & Advertising
We keep tracking to a minimum:
- No advertising — wedgewoodai.com does not show ads and does not load advertising scripts
- Essential cookies only — We use only the cookies needed for sign-in, security checks and your display preferences
- Transparent disclosure — Our Privacy Policy explains each type of cookie and its purpose
API Security
External API endpoints used by our applications are protected by:
- API key authentication — All inter-service API calls require a valid API key in the request header
- Input validation — Required fields are verified and data types are enforced
- Application-level access control — Emergency shutdown capability allows instant access revocation per-application or globally
Infrastructure & Platform
Our services run on the Abacus.AI platform which provides:
- Managed hosting with automatic security patches
- Isolated application environments
- Automated SSL/TLS certificate management
- DDoS protection at the infrastructure level
Security Checklist
Reporting Security Vulnerabilities
We take security seriously. If you discover a vulnerability in any of our services, we ask that you disclose it responsibly:
How to report:
Email: [email protected]
Our contact details are also published in machine-readable form at /.well-known/security.txt.
Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- The affected service or sub-domain
- Your contact information for follow-up
Our commitment: We will acknowledge your report within 48 hours and provide an estimated timeline for resolution. We will not take legal action against security researchers who report vulnerabilities responsibly.
If a security incident affects your personal information, we will follow the breach-notification commitments set out in our Privacy Policy.
Security is a shared responsibility
While we implement comprehensive security measures, we encourage users to protect their accounts by using strong passwords and enabling Two-Factor Authentication when available.
