Security claims should be as precise as the controls behind them.
TRENIC handles business and financial-record information, so access control, data separation, provider security and incident handling have to be treated as product requirements rather than marketing language.
Security principles
Access should be authenticated and scoped.
Business records should be available only through authorised access and should remain separated between users and business contexts.
Secrets belong on the server side.
Provider credentials and privileged keys should not be exposed in browser or client code.
Sharing should be controlled.
Any future sharing or accountant-access workflow should make scope, approval and revocation clear instead of turning a link into permanent authority.
Failures should not expose sensitive detail.
Error handling should avoid returning credentials, internal secrets or unnecessary personal information.
What users should do
- Use a strong, unique password for TRENIC.
- Keep email and device access secure because they may be part of account recovery.
- Do not send passwords, bank credentials, UTRs or tax documents through the general website contact route.
- Report suspicious access or unexpected account behaviour promptly.
What the website does not claim
TRENIC does not present a certification, penetration-test badge or third-party assurance as current unless that exact evidence is available for the released service. No online service is completely risk-free.
Report a security concern
Email founder@trenic.co.uk with the affected page or feature and a concise description. Avoid including customer records, credentials or other sensitive data unless it is necessary to explain the issue and a secure route has been agreed.