Trust

Security

How Theatrio keeps your theatre's information safe — encryption, hosting, backups, access controls and how to report a problem.

Last updated: August 2026

1.Our approach

This page is maintained by Theatrio to answer the common security questions committees ask before trusting us with their theatre's information. It describes the controls we have enabled today — it is not an independent audit or certification.

We keep security proportionate and practical: strong defaults, reputable infrastructure, and no unnecessary data collection.

2.Encryption

  • All traffic between your browser and Theatrio uses HTTPS/TLS.
  • Data stored in our database and file storage is encrypted at rest.
  • Requests to AI providers and Stripe are sent over encrypted connections only.

3.Password and account security

  • Passwords are stored only as salted one-way hashes — we can never read them.
  • Sign-in uses secure session tokens, which expire and refresh automatically.
  • Password reset links are single-use and time-limited.
  • Sign-in with Google is available if your committee prefers not to manage passwords.

Please use a unique password for Theatrio, and remove committee members from your account when their role ends.

4.Hosting and infrastructure

Theatrio runs on managed cloud infrastructure from reputable providers, with a managed database, file storage and authentication service. We do not run servers in someone's spare room. Payments are handled entirely by Stripe, a PCI-DSS Level 1 certified provider, and card details never reach our systems.

5.Backups

  • The database is backed up automatically by our managed provider.
  • Backups are encrypted and retained on a rolling schedule.
  • Deleted content cycles out of backups shortly after deletion, in line with our retention policy.

6.Access controls

  • Row-level security in the database means each theatre's data is only readable by that theatre's account.
  • Uploaded files are stored in private buckets, served through signed, expiring links.
  • Staff access is least-privilege and used only when needed to support you or investigate an issue.
  • Administrative access is protected by multi-factor authentication.

7.Monitoring and updates

  • Application errors and unusual activity are logged and reviewed.
  • Dependencies are updated regularly and security advisories are monitored.
  • Automated scanning flags common web and database misconfigurations.
  • If a personal data breach is likely to affect your rights, we notify affected customers and the ICO without undue delay.

8.Shared responsibility

Security works best as a partnership:

  • We secure the platform, infrastructure and data separation.
  • Your committee chooses strong passwords, controls who has access, and decides what is safe to upload — please avoid uploading sensitive personal data you don't need.

9.Responsible disclosure

If you think you have found a security vulnerability, please tell us before telling anyone else. Email info@theatrio.co.uk with enough detail to reproduce the issue.

  • We aim to acknowledge reports within 24 hours.
  • We will keep you updated while we investigate and fix.
  • Please do not access other customers' data, degrade the service, or run automated attacks.
  • We will not pursue action against researchers who report in good faith and follow this policy.

Business details

Business name
Theatrio
Legal status
UK sole trader (not a limited company)
Business address
4 Barton Court, Parkham, Bideford, EX39 5RJ, United Kingdom
Contact email
info@theatrio.co.uk