Information security
Information security
A conversation in InMyWords can hold the most sensitive thing a person has said to a public service. This is how it is protected.
Who this covers
INT6 Ltd, a company registered in Scotland, number SC547705, trading as INT6, which builds and holds InMyWords. It covers the application at app.inmywords.chat, this website and the server they run on. It is reviewed once a year and after any security incident.
The server
- Only Cloudflare can reach it. Every request comes through Cloudflare, and the server refuses at the connection any request that does not, so its address cannot be used to go around the protection in front of it.
- Encrypted in transit. Both sites are served only over HTTPS.
- A web application firewall. Every request is inspected by ModSecurity with the OWASP Core Rule Set before it reaches the application, and an address that keeps hitting errors is banned for an hour.
- Nothing runs a command. The application cannot start a program on the server, and can read and write only its own directory.
- The database is not on the network. It is reachable only from the server itself, and the application's account can reach its own database and no other.
- No shell for developers. Nobody who writes the software can sign in to the server. Changes arrive as a reviewed release, installed by the server's own administrator.
Signing in
- Passwords are hashed. A password is stored only as a one-way hash and cannot be read back by anyone, including us.
- A second factor. An authenticator app or a passkey can be required for a group by the organisation's administrators, and our own administration area always needs one.
- Repeated failures lock the account. Ten failed sign-ins lock it until it is unlocked; passkey attempts are limited per address.
- Sessions can be ended. Signed-in sessions are held on the server, so an administrator can see them and end one.
- Forms are protected. Every form that changes something carries a token tied to the session, so another site cannot submit it on a person's behalf.
Who can see what
- Permissions by group. Within an organisation, what a person may see and do is set by the group they are in, by the organisation's own administrators.
- An organisation can hold its people to its own network. It can list the addresses its people may reach InMyWords from, and the email domains that may hold an account.
- Our own access is recorded. When a member of our staff reads a conversation, to support a customer or investigate a fault, that read is written to the audit trail.
- Connections are limited. Software connected through the integrations API gets only the scopes the organisation gives it, its key is stored only as a hash, and every call is logged.
Releases
- Tested before they leave us. Every release is built and tested away from the live server.
- Rehearsed and checked. Each one is installed first on a copy of the live system, then checked on arrival by the server's administrator: checksums, a scan for secrets and for destructive database statements.
- One way back. A release that carries no rollback plan is not installed.
Data
- Stored for as long as the organisation decides. An organisation sets how long its conversations and records are kept, and can erase them.
- Backed up. The databases are backed up, the copies are kept away from the server, and the database is copied again before every release is installed.
- Content leaves only to be translated. What is sent to a language model, and what is not, is on use of AI.
Reporting a problem
If you think you have found a security flaw, see vulnerability disclosure. If you think your account or your organisation's data has been reached by someone who should not have it, tell us at once.
Document control
- Reference
- IMW-POL-005
- Version
- 01
- Release date
- 2 October 2026
- Status
- Released