Tell us where it breaksContact

Last updated 12 August 2026

Security

This page is for the person whose job is to ask. It says what we hold, who else touches it, how we work, and what we have not done yet. Where something is not in place, it says so rather than leaving a gap for you to discover.

What this website holds

Nothing. There is no form, no account, no cookie, no browser storage and no analytics of any kind. Fonts and images are served from this domain, so no request leaves for another company while you read this page. The privacy notice sets that out in full, and it is checked against the deployed site rather than asserted.

What we hold

Correspondence. If you write to us we hold your address, your name if you give it, and whatever you put in the message, in order to answer you and to keep a record of what was said. That is the entire dataset today. Pangalom Ltd has no product collecting data, no user accounts and no customer database.

Who else processes it

Two companies, and we would rather name them than describe them:

There is no third company. No customer relationship tool, no mailing platform, no analytics provider, no error tracker. If that list ever grows, this page changes before the tool is switched on, not after.

Where it is

Google and Cloudflare are United States companies running global infrastructure, so data may be processed outside the United Kingdom. Those transfers rely on the safeguards in each provider's data processing terms, including the UK Addendum to the standard contractual clauses. Ask and we will tell you which safeguard applies to what.

How we work

The practical controls in place today:

Your data and our models

We do not train anything on your data. Not our agents, not a shared model, not an internal dataset. What we learn from an engagement is how to build your system, and that stays with your system.

Where an engagement uses a model provider, we use it on terms that exclude training on the data we send, and we tell you which provider is involved before anything is built. An agent operates inside a written authority agreed in advance, which is the same boundary described in the six things every engagement includes.

If something goes wrong

Where we process data on your behalf and discover a breach affecting it, we will tell you within 48 hours of becoming aware, with what we know at that point rather than waiting for a complete picture. The 48 hours is deliberate, and so is the fact that it is not 24. UK GDPR gives you 72 hours to notify the regulator and that clock does not start until we tell you, so taking the full 72 ourselves would spend your deadline for you. What is left is a commitment a company this size can keep on a Saturday, which is the only kind worth writing down: a deadline that depends on one person being reachable is a deadline that will be missed once and then disbelieved.

Where we are the controller, which is the case for correspondence sent to us through this site, we notify the Information Commissioner's Office within 72 hours of becoming aware where the law requires it.

What we are not certified for

Pangalom Ltd holds no security certification today. Not Cyber Essentials, not ISO 27001, not SOC 2. We would rather write that down than let you find it out in a questionnaire.

Cyber Essentials is the one we intend to hold first, because it is the UK government scheme that matches the size of this company and the controls above are most of what it asks for. ISO 27001 follows when an engagement calls for it. If your procurement process requires a certification we do not have, tell us early and we will tell you honestly whether we can get there in your timeline rather than saying yes and hoping.

Reporting a problem

If you have found a security problem with this site or with anything we run, write to hello@pangalom.com. The same address is published at /.well-known/security.txt. We aim to acknowledge a report within three working days. One person reads that inbox, so that is a real number rather than a generous one.

Tell us what you did, what you saw, and enough for us to reproduce it. A short description beats a scanner report. There is no bug bounty and we do not pay for reports, which is worth saying plainly so nobody spends time expecting one.

What is in scope

pangalom.com and anything served from it. In practice that is four static pages, a stylesheet, one script and two fonts. There is no form, no login, no database and no API, so the surface is genuinely small and we would rather tell you that than waste your afternoon.

What is not

What we will and will not do

If you act in good faith, stay inside the scope above, do not access or alter data that is not yours, and give us a reasonable chance to fix the problem before you publish it, we will treat your testing as authorised and we will not bring a legal claim against you over it. We will tell you what we found and when it is fixed, and we will credit you if you want that.

Two limits on that promise, because a promise we cannot keep is worse than none. We can only speak for ourselves. We cannot grant permission on behalf of Cloudflare, Google, or anyone else whose systems sit under ours. And we cannot waive the criminal law. The Computer Misuse Act 1990 is not ours to set aside; no company's disclosure policy can do that, whatever it says.

Who we are

Pangalom Ltd, registered in England and Wales under company number 17365335, at 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.