Least privilege, by default
A new role starts with nothing and is granted what it needs. Nobody sees a record they should not because a permission was left switched on from last year.
Security & data protection
Everything below describes how our products are built and operated. TradeMate runs on your own PC rather than on our servers, so it works differently and has its own section. If you need any of it in a form your governors, your DPO or your insurer can sign off, ask and we will send the full documentation.
A new role starts with nothing and is granted what it needs. Nobody sees a record they should not because a permission was left switched on from last year.
Every read and write against sensitive data is attributable. If you are ever asked who saw a record and when, the answer exists.
Your data is yours, in a documented schema, exportable in full, at any time, at no charge. That is a design constraint, not a support policy.
Controls
OAuth 2.0 and OpenID Connect, so our products sign in against an identity provider you already run. Multi-factor and conditional access stay where you manage them.
Permissions are enforced server-side on every request. Hiding a button is a courtesy to the user; the API is where the decision is actually made.
Access to sensitive records is logged with the acting user, the record and the time — and kept long enough to be worth having.
Attachments are held outside the database in controlled storage, served through the same permission checks as the record they belong to.
Hosted deployments run in the United Kingdom. Self-hosted deployments run wherever you decide, including entirely on your own infrastructure.
Changes are peer-reviewed and covered by an automated test suite. Anything touching personal data, permissions or payments gets a second, security-specific review.
Sensitive records
A safeguarding note, a medical need, a consent form, a photo ID held because the law requires it — these are not simply more fields on a form. Our products treat them as a separate access boundary: visible to the people who are supposed to see them, invisible to everyone else, and logged either way.
Data protection
You are. A school is the controller for its pupil and staff data; a salon or clinic is the controller for its client records. Block acts as a processor, working on your documented instructions under a data processing agreement.
In the UK for hosted deployments. If you self-host, it never leaves your infrastructure at all — we have no standing access to a self-hosted instance.
A record can be exported in full, including the audit history attached to it, so an SAR is a task you can complete yourself rather than a support ticket to us.
You take a complete export in a documented format, and we delete what we hold to an agreed schedule. There is no exit fee and no proprietary lock on your own records.
Schools have a further set of questions — safeguarding as an access boundary, SEND and medical records, what follows a pupil on transfer. Those are answered in detail on myportaledu.com.
TradeMate
TradeMate runs on your Windows PC and keeps its records there. Because we never receive them, Block is neither the controller nor a processor of your TradeMate data, and the hosted controls above do not apply to it. What does apply is how it connects to HMRC.
We would far rather hear about a vulnerability from you than from a customer. Report it to hello@blocksoftware.uk and it goes straight to Rowan Richards, who owns security here. We will acknowledge it, keep you updated, and credit you if you would like us to.
Most organisations have one, and most of them ask the same forty questions. We are happy to complete yours, or to talk it through with your IT partner directly.