Reviewed 2026-09-03
Security approach and disclosure
How TechGeek UK approaches workload-specific security decisions, shared responsibility and website vulnerability reporting.
Public operating standard
Security is designed around the workload
A proposed system should be understood before it is secured. That means identifying what the system is for, who may use it, which information it handles, where it comes from, which external services or APIs are involved, which environments exist and what could go wrong. The appropriate control set is shaped by that context. An internal demonstrator, a public website and a production workflow handling sensitive information do not carry the same obligations or risk.
Where appropriate to the agreed architecture, a project may include measures such as least-privilege access, environment separation, secure configuration, secrets handling, logging, review, backups, rate limiting, monitoring and network protections. The fact that a control is technically available does not establish that it is configured for every project or sufficient for every risk. Selection, configuration, testing, documentation and ongoing ownership matter together.
Public operating standard
Shared responsibility and delivery boundaries
The client normally owns the business purpose, lawful and operational use, people authorised to decide, source-data rights, user access policy and acceptance of the project-specific risk. TechGeek’s role is agreed per engagement and can include design, implementation, evaluation, documentation and delivery support. Hosting, AI, identity, monitoring, email and edge providers operate their own services under their contracts and configurations. Their features and terms must be checked in the selected account and deployment context.
A project should make responsibilities concrete: who manages identities, approves configuration changes, holds recovery responsibilities, reviews logs or exceptions, maintains supplier settings, responds to an incident and decides whether to pause or change an AI workflow. A statement that a system uses cloud, AI or edge services does not transfer these responsibilities or establish a security outcome.
Public operating standard
AI, data and third-party services
AI-enabled systems need additional, workload-specific decisions about inputs, prompts, outputs, model providers, retention, evaluation, human oversight and acceptable use. Where a provider, account, endpoint and contract support an option such as reduced retention or no training, it can be assessed and documented for the proposed solution. It must not be assumed from a provider’s brand name or from a general website statement.
UK data residency, subprocessors, support access, backup location, cross-border transfer, encryption, service continuity and incident obligations are likewise architecture and contract questions. TechGeek does not make a blanket promise of UK-only processing, GDPR compliance or a particular provider configuration. The relevant commitments belong in project documentation once the workload and selected services are known.
Public operating standard
Website and vulnerability reporting
For this public website, TechGeek uses standard web-delivery controls and may use security services such as Cloudflare Turnstile, web application firewall rules, DDoS mitigation, bot controls or rate limiting where selected and configured. These are risk-reduction measures, not a zero-day, breach-prevention or availability guarantee. We do not ask researchers to bypass safeguards, access personal data, disrupt the service, publish credentials or test systems they do not own.
To report a suspected security issue affecting this website, email karan@techgeekuk.com with a concise description, affected URL or component, reproducible steps that do not expose data, and a safe way to contact you. Do not include credentials, exploit code, personal data or sensitive customer material. Reports are reviewed as circumstances allow; this route does not create a bounty programme, response-time commitment or permission to conduct intrusive testing.
Evidence boundary
What this page does not ask you to infer.
- 01
This route does not assert ISO certification, penetration-test coverage, compliance certification, partner status, insurance coverage, a security operations centre or a universal control baseline.
- 02
Use of Cloudflare or another provider is configuration-specific and does not guarantee protection against every vulnerability, attack, outage, human error or third-party failure.
- 03
Security and privacy requirements for a client workload are decided in the relevant engagement documentation, not inferred from the public site.
Direct answers
Questions buyers ask before the work starts
01Can TechGeek guarantee that our system will be secure?
No responsible provider can give an absolute guarantee. A project can identify risks, choose and test proportionate controls, assign responsibilities and monitor the operating system, but residual risk remains.
02Can you guarantee UK data residency?
No blanket guarantee is made. A project can assess workload-specific options, including locations, subprocessors, support access, backups and transfers, then record the agreed arrangement.
03Does Cloudflare protect against every attack?
No. Where selected, Cloudflare can be part of a layered approach. Actual protection depends on plan, architecture, configuration, application behaviour and the wider operating model.
04Can an AI provider be configured not to train on our data?
Where the selected provider, account, endpoint and contract support an option, it can be assessed. The applicable terms and configuration must be verified for the proposed workload.
05How do I report a website security issue?
Email karan@techgeekuk.com with a concise non-destructive report. Do not send credentials, exploit code, personal data or confidential material, and do not conduct intrusive testing without permission.
06Is this page a security policy for a future client project?
No. It explains the public approach and its limits. Project-specific controls, data processing, incident responsibilities and acceptance criteria are agreed in the relevant documents.
Source discipline
Primary guidance and technical references
A practical next step
Make the assurance question specific.
Describe the proposed workload, data, suppliers, access and release context so the relevant security decisions can be addressed without a blanket promise.
Discuss security and delivery