Last updated: 21 June 2025
Security Policy
At SoftwareForge (BellCorporateLabs Ltd), security is built into how we design, host, and deliver our software. This policy describes our approach and how you can report security concerns.
1. Our security principles
- Local-first by design — Business data in products like InvoiceEasy stays on your device unless you choose to share it.
- Minimal data collection — We avoid collecting data we do not need to operate our services.
- Defence in depth — We combine secure hosting, encrypted transport, and careful third-party selection.
- Transparency — We document how our products work so you can make informed decisions.
2. Website and infrastructure
Our public website and web applications are delivered over HTTPS (TLS). Key measures include:
- Hosting on reputable cloud platforms with regular security patching (Vercel)
- DNS and edge protection via Cloudflare
- Static or minimal server-side attack surface on marketing pages
- Security headers and content security policies where applicable on product web apps
3. Payments and licensing
All payment processing is handled by Lemon Squeezy. We do not store full payment card details on our systems. License validation uses Lemon Squeezy's API over encrypted connections.
4. InvoiceEasy and local data
InvoiceEasy stores invoices, clients, and settings locally in your browser or desktop application. Because your business data is not uploaded to our servers for normal operation:
- There is no central database of your invoice content for us to breach
- You control backups via export features in the app
- You are responsible for securing the device where the app runs
The web version validates licenses by contacting Lemon Squeezy's API. The desktop app runs with standard Electron web security settings enabled.
5. Software updates
We release updates to address bugs and security issues. We recommend keeping desktop installers up to date and using the latest deployed web version. Security fixes may be distributed through GitHub Releases or automatic redeployment of the web app.
6. Access control
Internal access to production systems, domain registrars, payment dashboards, and source code is limited to authorized BellCorporateLabs personnel. We use strong authentication and least-privilege access where supported by our providers.
7. Incident response
If we become aware of a security incident affecting customer data or our services, we will investigate promptly, take steps to contain and remediate the issue, and notify affected users or regulators where required by law.
8. Responsible disclosure
We welcome reports from security researchers and customers. If you believe you have found a vulnerability in our website or products, please contact us at support@bellcorporatelabs.com with:
- A clear description of the issue
- Steps to reproduce (if applicable)
- Any relevant screenshots or proof-of-concept details
Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and address them. We will acknowledge good-faith reports and work with you to resolve confirmed issues.
9. Your responsibilities
- Keep your license key confidential
- Use a secure, up-to-date browser or operating system
- Protect backups you export from the application
- Report suspicious activity related to your purchase or license
10. Changes to this policy
We may update this Security Policy as our products and infrastructure evolve. Check the "Last updated" date at the top of this page for the current version.