Security at Music Intel.
We are an early-stage UK company with a forensic-data background. We take security seriously because our entire product depends on it. This page describes the practices we actually follow today, what we are working towards, and where we are not yet.
Encryption.
All traffic between you and our services is encrypted in transit using TLS 1.2 or 1.3. HSTS is enforced on the app domain.
Customer data and operational databases are encrypted at rest using disk-level encryption on the underlying hosts. Access tokens for connected platforms (OAuth: Meta, Google, Spotify) are encrypted with a separate key before being written to the database.
Hosting and data residency.
Primary hosting is in the UK and EU. Production infrastructure runs on managed Linux hosts under our own administration; we do not co-mingle customer data on shared multi-tenant SaaS where avoidable.
Where a restricted transfer requires safeguards, we use an approved mechanism such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with the required data-protection test or transfer risk assessment.
Service-specific provider roles and assurance documents are confirmed during due diligence. Where Music Intel will act as a processor, the required Article 28 terms must be agreed before processing begins. Contact legal@musicintel.co.uk.
Access control.
Production access is role-based, with least-privilege as the default. Admin actions are logged. Production credentials are rotated on schedule and on-event (departure, suspected exposure, key compromise).
No single person can unilaterally access raw customer data without the action being logged.
What we collect, what we don't.
We minimise. Groove and Google Analytics are not loaded on supported public pages unless a visitor accepts the relevant Performance or Marketing choice. Groove then uses a first-party pseudonymous identifier, browser/device signals and on-site interaction summaries. Meta Pixel and customer-configured TikTok campaign measurement load only after Marketing consent. See our Cookie Policy and Privacy Policy.
The Musicata platform does not store full IPs longer than necessary for the operation that captured them; visitor records are aggregated within 30 days.
We do not sell customer data. We do not share customer data between tenants. We never train external machine-learning models on customer data.
Full breakdown: Privacy Policy.
Vulnerability disclosure.
If you have found a security issue, please tell us before disclosing publicly. Email security@musicintel.co.uk.
Our security.txt file follows RFC 9116 and lists the same contact.
We do not currently run a paid bug-bounty programme. We will acknowledge responsible disclosures and credit researchers on request.
Incident response.
When Music Intel acts as processor, we notify the relevant controller without undue delay after becoming aware of a personal-data breach. When Music Intel acts as controller, we notify the ICO within 72 hours where legally required, and affected people without undue delay where the breach is likely to result in a high risk.
Operational incidents (outages, degraded service) are communicated by email to active customers. Our public live-probe status page reports current service checks; a historical dashboard and incident timeline remain on the roadmap.
What we do not yet have.
We are early-stage. We are not yet certified to ISO 27001. We are not yet certified to SOC 2. We are working towards Cyber Essentials (UK government-backed assurance scheme) as the first formal milestone.
If your procurement process requires a specific certification we do not yet hold, tell us early. We will identify whether the evidence and contractual safeguards available for the proposed scope meet the requirement. If they do not, we will say so.
Security questions, audit requests, DPA enquiries: security@musicintel.co.uk
