Last updated: 27 August 2026

This Security & Monitoring Policy describes the principles used by Westport Digital Limited to protect GamiTrend Software operations and explains the shared responsibilities that apply when customers configure authorised monitoring.

1. Security objectives

Our security programme is designed to support confidentiality, integrity and availability appropriate to the nature of our website, order process and monitoring products. We apply risk-based technical and organisational controls and review them as our services, suppliers, threats and legal obligations change.

No organisation can guarantee absolute security. The controls described here reduce and manage risk; they do not eliminate every possibility of error, unauthorised access, outage or malicious activity.

2. Shared responsibility model

We are responsible for reasonable safeguards within the GamiTrend Software service and for administering our suppliers and access. Customers remain responsible for the security, legality and continuity of their own websites, accounts, networks and targets, including backups, patching, password security, access control, firewall rules, recovery and incident response.

A monitoring alert is an operational signal, not a substitute for secure configuration or human investigation. Customers should validate significant alerts using their own logs and procedures.

3. Data minimisation and secure configuration

We seek to collect and retain only information reasonably necessary to process an order, configure the purchased check, deliver alerts, provide support, prevent abuse and meet legal obligations. Customers should avoid submitting sensitive data that is not required.

Monitoring configurations should use the least privileged method capable of performing the intended check. Public endpoints should be used where suitable. Credentials, secret keys, private certificates and full payment-card information must not be sent by ordinary email or placed in a target URL.

4. Access control

Administrative and operational access is limited according to role and business need. We use account controls, least-privilege principles and access review appropriate to the systems involved. Personnel and providers with access to personal or confidential information are expected to protect it and use it only for authorised purposes.

Customers must protect their own access information, use strong unique passwords, enable multi-factor authentication where available and remove access from people who no longer require it.

5. Encryption and communications

We use encrypted transport, such as HTTPS/TLS, for supported web and service communications where appropriate. Encryption reduces interception risk in transit but does not make an insecure endpoint, compromised device or exposed credential safe.

Email is not an appropriate channel for high-risk secrets. If support requires sensitive configuration, we will aim to use a method suitable for the nature and risk of the information.

6. Hosting, network and supplier security

We use professional hosting, network, content-delivery, email, payment and operational providers selected for legitimate business functions. We consider the nature of the service, access, contractual safeguards and security posture when engaging providers and limit the information shared to what is reasonably necessary.

Third-party infrastructure can still experience outages or security events. We monitor material dependencies and take reasonable steps to maintain or restore service, but we do not control every external network or supplier.

7. Logging, monitoring and abuse detection

We may maintain security, access, transaction, configuration and diagnostic logs to identify abnormal activity, investigate incidents, troubleshoot service problems, prevent fraud and enforce our policies. Access to logs is limited according to operational need and retention is based on purpose, risk and legal requirements.

We may apply rate limits, automated indicators and manual review to identify abusive traffic, account takeover, unauthorised targets, payment fraud or interference with the platform.

8. Vulnerability and update management

We aim to keep systems and components within our control supported and appropriately updated. Reported or discovered weaknesses are assessed according to severity, exploitability and potential impact, and remediation is prioritised on that basis.

Customers remain responsible for vulnerabilities in their own targets, applications, plugins, code and providers. Our standard monitoring products do not constitute penetration testing or a comprehensive vulnerability assessment unless a product expressly states otherwise.

9. Payment security

Payments are handled by the providers made available at checkout. We do not ask customers to provide complete payment-card numbers by email and do not intentionally store full card details in ordinary website, order or support records. Payment providers may conduct their own authentication, fraud and regulatory checks.

A transaction may be delayed, declined or reviewed where payment or fraud indicators require it. We limit internal use of payment references to order administration, refunds, support, accounting and dispute management.

10. Backups, continuity and recovery

We use proportionate backup and recovery measures for systems within our control and maintain procedures intended to restore important functions after disruption. Recovery time can depend on the nature of the incident, third-party infrastructure and the integrity of available backups.

Our measures do not back up a customer’s website, server, database or application unless a purchased product expressly provides that function. Customers must maintain independent backups and tested recovery procedures for their own systems.

11. Security incident response

When we identify a suspected incident, we assess available evidence, contain risk where practicable, protect affected systems, investigate cause and impact, restore service and record lessons for improvement. We may suspend a configuration or access temporarily where necessary to protect customers, third parties or the platform.

Where a personal-data breach creates a legal notification obligation, we will notify the relevant authority and affected individuals as required. Communications will be based on verified information available at the time and may be updated as the investigation develops.

12. Customer reporting

Suspected account compromise, unauthorised monitoring, exposed access information or a service-related vulnerability should be reported promptly to support@gamitrendsoftware.com. Include sufficient detail to reproduce or investigate the concern but do not exploit a weakness, access another person’s data, disrupt service or publicly disclose sensitive details before we have had a reasonable opportunity to respond.

We will acknowledge credible reports and prioritise them according to potential impact. We do not authorise testing that violates law, third-party terms or our Acceptable Use Policy.

13. Authorised monitoring controls

Customers may configure only targets they own, administer or have explicit authority to monitor. We may request evidence of authority, apply rate or target limits, investigate a target-owner complaint and suspend activity that creates legal, security or operational risk.

Monitoring checks are intended to observe specified conditions. They must not be used for exploitation, password attacks, denial of service, circumvention or covert surveillance.

14. Monitoring accuracy and alert delivery

Results depend on configuration, interval, network path, location, provider availability and target response. False positives, false negatives, delayed or duplicated alerts can occur. Customers should maintain more than one appropriate control for critical systems and ensure alert destinations remain current and monitored.

15. Retention and disposal

Security and service records are retained only for as long as reasonably necessary for delivery, support, fraud prevention, security investigation, accounting and legal obligations. Retention varies by record type and risk. When information is no longer needed, we delete, anonymise or securely restrict it in accordance with our operational processes.

16. Review and improvement

We review controls when material changes, incidents, supplier changes, legal developments or risk assessments indicate that an update is appropriate. Policy updates are dated and do not reduce mandatory rights or obligations.

Security reminder: Do not rely on a single monitoring alert as the only protection for a critical service. Maintain backups, access controls, patching, independent logs and a tested response plan.

17. Contact

Security and monitoring enquiries: support@gamitrendsoftware.com. Westport Digital Limited, company number 17275791.