Encrypted everywhere
All traffic runs over HTTPS and is pinned with HSTS, so data in transit is encrypted between you and us.
Security is part of how this site is built, not an afterthought. Here is what protects you and your data, in plain language.
All traffic runs over HTTPS and is pinned with HSTS, so data in transit is encrypted between you and us.
Card details go straight to Stripe (a PCI DSS Level 1 provider). We never see, touch, or store card numbers.
The admin area sits behind a signed, expiring gate and is invisible to the public. Only staff and admins can reach it.
Rate limiting on forms, login, booking, and payments, plus a decoy login that traps and logs automated probes.
A Content Security Policy, anti-clickjacking, no MIME-sniffing, a strict referrer policy, and secure HttpOnly cookies.
Essential cookies keep the site running. Optional analytics and embedded maps load only after you accept - decline and only essential cookies are used.
We welcome reports from security researchers and customers. If you believe you have found a vulnerability, email hello@invisionnetwork.org (see our security.txt). Please give us a reasonable chance to fix the issue before disclosing it publicly. We will not pursue legal action for good-faith research that respects our users' privacy and data.
Our engineering and privacy practices are designed for and aligned with widely used standards: the OWASP Top 10 for web application security, WCAG 2.1 AA for accessibility, GDPR-aware privacy handling, and PCI DSS awareness for payments (via Stripe). We do not claim any formal certification unless an independent audit has been completed.
We aim to meet WCAG 2.1 AA. The site provides visible keyboard focus, honours reduced-motion preferences, uses readable contrast and large tap targets on mobile, includes descriptive text for images, and uses semantic, screen-reader-friendly markup. If any part of the site is hard to use, tell us at hello@invisionnetwork.org and we will fix it.
See also our Privacy Policy and Terms of Service.