This page describes how this website is built and protected. The security of the campaign platform itself is a separate and much longer conversation, and we walk through it in the briefing.
Version 1.0 · 15 September 2026
The short version. This site is a static page with one form. It has no database, no login, no user accounts and no stored submissions. An enquiry becomes an email and nothing else. There is very little here to steal, which is the strongest security property a brochure site can have.
The form posts to a small piece of code running on our hosting provider's edge network. That code:
Bot protection is deliberately quiet: a blocked submission receives the same response as an accepted one, so an automated attacker learns nothing from the difference.
An enquiry passes through our hosting provider, a transactional email service, and our own mail provider, before arriving in the mailboxes we read. Each of those is named, with its location, in the privacy notice — we would rather you could see the whole chain than be told it is "secure".
Mail we send from this domain is cryptographically signed with DKIM, and the domain publishes SPF and DMARC records. That is what lets your mail provider verify that a message claiming to come from suffrage.ai genuinely did.
We would rather be trusted than impressive, so:
If you think you have found a security problem with this site, please tell us.
Email [email protected] with "Security" in the subject line. Describe what you found and how to reproduce it.
We will acknowledge within two business days and keep you informed while we fix it. We will not take legal action against anyone who reports a genuine issue to us in good faith, who does not access or alter data belonging to anyone else, and who gives us a reasonable opportunity to fix it before telling anyone else.
Please do not run automated scanners against the site. It tells us very little and costs us real money in bandwidth.
If a breach affects personal data you have sent us, we will assess it immediately, tell the Information Commissioner's Office within 72 hours where the law requires it, and tell you directly without undue delay where the risk to you is high. We will tell you what happened, what it means for you, and what we have done about it.