Filing Guardian
Security and data

What this product is, and what it holds

The honest answer is that Filing Guardian is small, and small is a security property.

What it is

The whole product is static pages, four small serverless functions, and one private data store. There is no database behind it, no third-party trackers, no ad pixels, and no cookies. Most of what you can do on this site involves no server at all.

The demo does all of its work in your browser.

When you look up your company's deadlines in the demo, the dates are computed on your own machine, from a rule book shipped to the page as data. The dates and details you type are never sent to us. The only thing the demo reports back is an anonymous daily count: that the page was viewed, which ticker was looked up, the tag on the link that brought you, and the referring site's hostname. The rule book page and the pre-listing calendar go further still: they compute everything in your browser and report nothing back to us. Like every page on this site, they do load their fonts from Google Fonts; that request goes to Google, not to us, and our privacy notice discloses it.

Pages

Static HTML, served over TLS. No page assembles itself from a database.

Functions

Four small serverless functions: the pilot form, the page counter, the sign-in, and the founder's own contact list.

Storage

One private store that only the functions can reach. Nothing in it is served to the public.

Not present

No database, no third-party trackers, no ad pixels, no cookies.

What we store

Four surfaces touch a server. Here is each one, what it keeps, and what it refuses to keep.

SurfaceWhat is storedWhat is never stored
Pilot form Only the fields you type: your email (the one required field), and if you choose to give them, your name, company and role. If you tick the consent box, a consent flag with the time you ticked it. The box is unchecked by default and always optional. A single-use confirmation link is emailed to you and expires in 24 hours. Card details. Billing is by invoice, so no payment card ever touches this site. Your raw IP address is not stored either; a one-way hash is used only to cap signups from one connection per day, and consent is never assumed on your behalf.
Page counts Daily totals only: which page was viewed, the source tag on the link that brought you (for example a WhatsApp or LinkedIn link), the referring site's hostname, and on the demo, which ticker was looked up. Your IP address, your user agent, any cookie, any identifier of any kind. A count of twelve views is exactly that: the number twelve, with no record of who the twelve were.
Founder's outreach list The founder keeps his own list of listed-company officers (names, roles and published contact details compiled from public filings and the JSE's own lists) in the same private store, behind the same sign-in, for running the pilot outreach. It is personal data under the Jamaica Data Protection Act and is treated that way: held privately, never shown on any page, and removed on request. Anything a visitor typed. This list is compiled from public sources, not from this website's forms, and it is never shared, sold, or used for anything except the founder's own outreach.
Sign-in A hash of the founder's dashboard password, held in server configuration, and a signed session token that lives in the signed-in browser. There are no visitor accounts on this marketing site; the dashboard a pilot company signs into is covered in the next section. The password itself, anywhere, in any form. Failed attempts are counted briefly in memory to slow guessing and are forgotten within minutes; they are never written to storage.

Nothing you enter here is shared with, or sold to, any other product or company.

The dashboard a pilot company signs into

The table above is the public site. When your company joins the pilot, you also get a signed-in dashboard, and it holds more than the site does: your filing dates, the names, roles and email addresses of the people on your reminder ladder, the log of every reminder and sign-off, and any figures you choose to import for your report.

Who can see it is a short list: the people you name, and the founder, who runs the product and sets it up with you. It lives in the same private store described above, behind the same protections listed below, and nothing in it is used for anything except running your reminders and your record.

Your record is yours to take. You can export it at any time, during the pilot and after it, and if you leave, you leave with it. One commitment in writing: if Filing Guardian ever shuts down, every company gets its full record delivered to it and its data deleted, with notice before anything is switched off.

How the little we hold is protected

What we do not claim

There are no certifications to show you, and this page will not imply any. Badges belong to companies that have earned them, and we have not yet been through any such audit.

What we can say plainly is this: the product holds deliberately little. The strongest protection on this page is not a control at all, it is the data we decided not to collect. A store that contains a short list of pilot signups, some daily page counts and the founder's own outreach list is a small prize, guarded accordingly, and the outreach list is the part treated most carefully, because it is other people's personal data.

If your company reviews vendors with a security questionnaire, send it to hello@filingguardian.com. The founder's professional background is cybersecurity, and he answers every questionnaire personally rather than through a portal or a template.

Reporting a vulnerability

If you find a security problem on this site, email hello@filingguardian.com with the subject Security. You will get a fast acknowledgement from a person, a fix as quickly as we can manage, and a plain thank you. There is no bounty program.