Security Approach

Keeping your data safe and secure is important to us. We aim to protect your Manual of Me from unauthorised access, misuse, and loss, while keeping it available when you need it.

Below is an overview of the measures we take, and the responsibilities we all share.

1/ Passwordless access

We do not use or store passwords. Access to your Manual of Me is provided via secure email-based magic links.

Magic links expire after a short period of time (currently 30 minutes). This reduces the risk of unauthorised access, even if an old link is discovered. The security of this approach relies on the security of your email account.

2/ Secure hosting

Access to our application and databases is restricted to authorised personnel only.

Our infrastructure is hosted with a European-based hosting provider, using Amazon Web Services (AWS). AWS data centres are certified against recognised security standards, including:

These certifications relate to AWS infrastructure rather than to Manual of Me as a product.

3/ Monitoring and security testing

Our hosting provider conducts third-party security testing at intervals using independent security researchers.

Identified issues are assessed, prioritised, and addressed by our hosting and engineering teams. We also monitor system and user activity for signs of abuse or misuse, using a combination of automated systems and human review.

4/ Backups and redundancy

We maintain regular, rolling backups of application data.

Backups are stored in encrypted form and in separate systems to support recovery in the event of data loss, system failure, or other incidents.

5/ Privacy and data access

We do not sell your data.

We only share personal data with third parties where necessary to operate the service (for example, email delivery), or where legally required. Details are set out in our Privacy Policy.

You may request:

Our full Privacy Policy is available at: https://www.manualof.me/about/privacy

6/ Maintenance and downtime

From time to time we may need to carry out maintenance or updates that temporarily affect availability.

Where possible, planned maintenance is carried out outside of peak usage times. We aim to communicate planned downtime in advance via the website.

7/ Incident communication

If we become aware of a significant service issue or data security incident that materially affects users, we will communicate this within a reasonable timeframe, along with information about the impact and the steps being taken to address it.

8/ Reporting issues

If you believe you have identified a security issue, functional problem, or data concern, please contact us as soon as possible so we can investigate and respond.

9/ Your responsibilities

While we take reasonable measures to protect the platform, no system is risk-free.

You remain responsible for the content you choose to store in Manual of Me. We recommend maintaining your own backups of important content, for example by downloading a copy of your Manual or exporting it for storage elsewhere.

10/ Questions or concerns

We recognise that different individuals and organisations have different security and compliance requirements.

If you have questions, concerns, or specific requirements, please contact us at hello@manualof.me and we will do our best to help.

11/ Responsible disclosure

If you believe you have identified a security vulnerability, please report it responsibly and in good faith.

Please email details to security@manualof.me or hello@manualof.me, including:

Please do not publicly disclose vulnerabilities before giving us a reasonable opportunity to investigate and address them.

We do not operate a public bug bounty programme and do not offer financial rewards for vulnerability reports.

Manual of Me