Skip to main content
More Enquiries. More Clients. On Autopilot.
Aurora Digital - More Enquiries. More Clients. On Autopilot
Aurora Digital - More Enquiries. More Clients. On Autopilot
Policy
Security & Data Protection Policy - Aurora Digital

Security & Data Protection Policy

At Aurora Digital, we build and manage websites, CRM systems and digital marketing systems with security, reliability and data protection in mind.

This page explains the practical steps we take to protect websites, client systems and personal data. It is not an official Cyber Essentials certification, but it reflects the security-minded approach we apply when managing digital systems for ourselves and our clients.

1. Secure Hosting & Infrastructure

Websites managed by Aurora Digital are hosted using secure, reputable hosting infrastructure. We currently use SiteGround for managed WordPress hosting.

Our hosting approach includes:

  • SSL certificates enabled to protect website traffic via HTTPS
  • Daily automated hosting backups with restore points
  • Server-level security features provided by the hosting platform
  • Regular monitoring of website performance and availability

2. WordPress Security Hardening

We apply a range of WordPress hardening measures to reduce common security risks and protect websites from unauthorised access.

These may include:

  • Forcing HTTPS across the entire website
  • Keeping WordPress core, plugins and themes updated
  • Manually applying updates to reduce the risk of automated updates breaking a site
  • Disabling XML-RPC where it is not required
  • Limiting login attempts and applying brute-force protection
  • Enabling two-factor authentication (2FA) for admin access
  • Using strong passwords and avoiding common admin usernames
  • Using a custom login URL where appropriate
  • Disabling file editing from the WordPress dashboard
  • Locking and protecting sensitive system folders
  • Hiding the WordPress version where appropriate
  • Disabling the themes and plugins editor
  • Disabling unnecessary RSS and Atom feeds where appropriate
  • Applying firewall or security-layer protection
  • Deleting default files such as readme.html where appropriate
  • Disabling directory browsing
  • Using a non-default database prefix where appropriate
  • Limiting user roles and permissions
  • Using malware scanning and integrity checks

3. Updates & Maintenance

WordPress, plugin and theme updates are applied manually rather than automatically.

This allows us to review updates before applying them and reduce the risk of unexpected conflicts, layout issues or broken functionality.

Where required, updates are tested, reviewed and applied as part of an ongoing maintenance process.

4. Backups & Recovery

Backups are an important part of website protection and recovery planning.

Websites hosted through our managed setup benefit from daily automated backups provided by SiteGround.

In addition, manual backups are taken once per month and stored on an external hard drive for added protection.

5. Access Control

We limit access to websites, systems and client accounts to those who need it.

Our access control approach includes:

  • Admin access limited to Aurora Digital and trusted partners where required
  • Client access restricted to the permissions needed for their role
  • Strong passwords used across key systems
  • Two-factor authentication enabled for WordPress administrator access
  • Careful handling of login credentials and account access

6. CRM & Client Data Protection

Aurora Digital uses GoHighLevel for CRM, messaging, automation, forms, chat and lead management.

Client and customer data may be stored inside GoHighLevel where it is required to provide services, manage enquiries, automate follow-up or support marketing activity.

We do not export, share or transfer client data externally unless required for the delivery of agreed services, legal obligations, or with appropriate authorisation.

7. Payments & Card Data

Payments are handled securely through Stripe.

Aurora Digital does not store card details on its website. Payment information is processed directly by Stripe in accordance with Stripe’s own security and compliance standards.

8. Email, Outreach & Messaging

We use GoHighLevel for CRM communication, email, SMS, chat and automation workflows.

We may also use Apollo.io for business-to-business outreach and lead generation activity.

Where outreach or marketing activity is carried out, we aim to handle data responsibly and in line with applicable data protection requirements.

9. Third-Party Platforms

Some systems we build and manage rely on trusted third-party providers, including hosting platforms, CRM systems, analytics tools, payment processors and email platforms.

Each third-party provider is responsible for its own security, availability and data handling practices.

Where possible, we choose reputable providers with established security standards.

10. Client Responsibilities

Security is a shared responsibility. Clients are responsible for:

  • Keeping their own passwords secure
  • Not sharing login details unnecessarily
  • Informing us promptly if they suspect unauthorised access
  • Using appropriate access permissions for their team
  • Keeping any third-party accounts secure
  • Ensuring the content and data they provide is lawful and accurate

11. Ongoing Improvement

Security is not a one-time task. We regularly review the tools, processes and practices we use to manage websites and digital systems.

As technology, risks and best practices evolve, we aim to improve our approach so that client systems remain structured, reliable and protected.

12. Contact

If you have any questions about how we protect websites, systems or data, please contact us:

Email: success@auroradm.co.uk

Aurora Digital - More Enquiries. More Clients. On Autopilot
More Enquiries. More Clients. On Autopilot.
Operating Location

Poulton-Le-Fylde, Lancashire
Working with clients across the UK

Registered Office

167–169 Great Portland Street
5th Floor, London
W1W 5PF

Registered office address for correspondence. Day-to-day operations are run remotely in Poulton-Le-Fylde, Lancashire FY6 7ZD.

Contact