Security & Trust
Confidentiality is a design requirement, not a policy page.
The matters Rexton handles are frequently sensitive. That shapes how the practice operates day to day, and it shapes how the Rexton technology platform is being engineered. This page describes both, plainly.
This Website
What’s actually true about this site today.
We’d rather state a small number of concrete, verifiable facts than a long list of vague assurances. As implemented in this codebase:
- All traffic is served over HTTPS, with HSTS configured to keep it there.
- A restrictive Content-Security-Policy is set: no third-party or inline scripts by default.
- No analytics, trackers, or third-party scripts are loaded by default.
- The contact form collects only the fields needed to respond to an enquiry.
- Standard security response headers are set (X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy).
- No secrets or credentials are stored in this repository.
Full detail — including what still depends on hosting configuration — is tracked in the project’s SECURITY-REVIEW.md, which is maintained alongside this site’s source.
The Platform
The same principle, at the platform level.
We don’t publish the internal architecture of the Rexton platform here — in the same way we wouldn’t publish the internal workings of how a matter is run. What we can say is what it’s designed around:
- Human authority
- Decisions that require professional judgment are designed to come back to a person — not proceed on the platform’s own assumption.
- Governed action
- Where the platform can take real-world action, that action is designed to require deliberate authorization rather than happen as a side effect.
- Provenance
- Material claims and outputs are designed to be traceable to their source.
- Confidentiality by default
- Matter and client information is treated as sensitive from the start, not classified as sensitive only after a problem.
More on the thinking behind this is on the Rexton Technology page.
Reporting a Concern
Found a problem? Tell us.
If you believe you’ve found a security vulnerability affecting this website or Rexton’s systems, please use the contact page and mark your message as a security report. Please don’t include sensitive proof-of-concept detail in the initial message — describe the issue in general terms and we will follow up on a more appropriate channel.
Related
Privacy and data handling.
For how personal data is collected and used on this website, see our Privacy Notice and Cookie Notice.