Keeping your information and your business accounts safe is part of doing marketing properly. This page explains how we protect them.
Website and form data
- The site is served only over HTTPS through Cloudflare, with DDoS protection and security headers.
- The site is static. The only server code is the free audit form endpoint, which validates every field, limits submission size and rate-limits repeated submissions.
- Audit submissions are stored in a Cloudflare D1 database that only authorised staff can access. We store a salted hash of your IP address rather than the IP itself.
- We collect only the information needed to prepare your audit.
Client accounts
- Where platforms allow it, we ask to be added as a partner or with a role (such as Meta Business Suite roles) rather than asking for your password.
- If a password must be shared, we store it in a password manager, never in chats or documents, and ask you to change it when our work ends.
- We recommend and help you turn on two-factor authentication for your business accounts.
- Access is removed when an engagement ends.
Our team
- Staff accounts use strong passwords and two-factor authentication.
- Access to client data is limited to the people working on that client.
- We keep our tools and devices up to date.
Report a vulnerability
If you think you have found a security issue on growthhubnp.com, email hello@growthhubnp.com with the subject “Security report” and details of how to reproduce it. Please give us reasonable time to fix it before any public disclosure, and do not access or change other people’s data. We will acknowledge valid reports and keep you updated.