Security

Security

How THRive handles website, enquiry and service security.

Security

Last updated: July 2026. THRive is designed for teams handling HR, payroll, expenses and employee information. This page explains the practical security measures used around the website and enquiry process.

Website and form security

The website is maintained with controlled admin access, WordPress updates, monitored form handling and security checks intended to reduce spam, misuse and unauthorised access. Enquiry details should only be available to people who need them for sales, support or service follow-up.

Access control

Administrative access should be restricted to authorised users. Strong passwords, role-based access and multi-factor authentication should be used where available. Access should be reviewed when team members change role or leave.

Data handling

General website forms should be used for business enquiries and demo requests, not for sending live payroll files, medical records or sensitive employee data. Where more detailed information is needed, the team should provide an appropriate channel.

Hosting, backups and updates

The website and supporting systems should be maintained with secure hosting, regular updates, backup processes and recovery procedures proportionate to the information being handled.

Suppliers and related services

THRive may use trusted suppliers for hosting, email delivery, forms, analytics, security tools and related ITCS services. Supplier access should be limited to what is needed to provide the service.

Incident response

If a security issue is suspected, it should be investigated promptly, contained where possible, and escalated to the appropriate technical and management contacts. Where a personal data breach creates a legal reporting obligation, the relevant notification process should be followed.

For security questions, contact THRive on 01656 534 725.