Security & Trust

How Function Labs Approaches Security

Function Labs builds its own products and works on customer applications, so security needs to be practical rather than just a policy statement. This page describes the controls currently used on the main Function Labs website and the principles we apply to customer work.

Last reviewed: 27 August 2026

Restricted data access

Website enquiry, waitlist and marketing-consent records use access rules that allow public submission where needed but restrict reading and management to authorised administrators.

Server-side validation

Public enquiry and support functions validate required fields, enforce maximum lengths and normalise inputs on the server rather than relying only on browser validation.

Abuse and injection protections

Public forms use bot-trap fields and short-term rate limiting. Email handling validates addresses and rejects header-injection characters before user-supplied addresses are used in mail headers.

Privacy-focused analytics

Analytics is opt-in. Event properties are allow-listed and deliberately exclude names, email addresses, telephone numbers, full messages, app URLs and authentication tokens.

AI support boundaries

The support assistant provides general help and can escalate serious issues to human support. It is instructed not to request passwords, payment-card details, authentication codes or other secrets.

No exaggerated certification claims

This page describes controls we have actually implemented. Function Labs does not claim ISO 27001, SOC 2 or another security certification unless and until such a certification is formally obtained.

Platform and Infrastructure

The Function Labs website and a number of our applications use Base44's managed platform for hosting, databases, authentication, functions and other platform services. Function Labs is responsible for the application-level configuration and controls we implement; underlying platform security and availability also depend on the provider. External connectors such as Gmail are authorised through managed connector mechanisms rather than exposing provider access tokens in the public website interface.

Data Minimisation

Public forms ask for information relevant to the enquiry or support request. Analytics events use a restricted property allow-list. We ask users not to submit passwords, card details, authentication codes or other unnecessary secrets through ordinary forms or support chat. See our Privacy Policy for how website data is used and retained.

Gravity and Customer Applications

Security requirements vary by product and customer implementation. Gravity uses role- and permission-based access patterns for workforce functions, and customer-specific data-processing or security responsibilities may be documented in the relevant order, project terms or data-processing agreement. For customer Base44 applications, we review application-level permissions, data models, backend functions and risky public pathways as part of security-focused review work where included in scope.

Third-Party Services

Apps can depend on platforms, APIs, payment providers, app stores and other external services. No provider or internet-connected system can be guaranteed completely secure or continuously available. We design around those dependencies where practical and avoid promising security properties that we do not control.

Report a Security Concern

If you believe you have found a security issue involving this website or a Function Labs product, email support@functionlabs.co.uk with the subject “Security Report”. Include enough detail for us to understand and reproduce the issue, but do not include passwords, authentication tokens, payment-card data or personal information that is not necessary for the report.

Please do not access, alter, download or retain data belonging to other users in order to demonstrate an issue. We do not currently operate a public bug-bounty programme, so do not assume testing activity is authorised beyond normal use of the service.

Company Details

Function Labs Limited

Company No. 17129741 · Registered in England and Wales

Registered office: Unit 13 Freeland Park, Wareham Road, Lytchett Matravers, Poole, England, BH16 6FA

support@functionlabs.co.uk