Security

Last updated 29 September 2026

This page describes how we protect LastLook and the information in it, what we ask of the organisations that use it, and how to report a security concern. It summarises our current practices, which change over time, and is not a certification or a guarantee: no system is completely secure.

1. Our approach

We protect the service with administrative, technical and physical safeguards appropriate to the information it holds, and we review them as the service changes. This page is provided for information and summarises those safeguards; our commitments to customers are set out in our Terms of Service.

2. Hosting and infrastructure

LastLook is hosted on Laravel Cloud, a managed application platform that runs on infrastructure operated by a major cloud provider, which is responsible for the physical security of its data centres.

We serve the service over encrypted connections (HTTPS), and we run it in production environments that are kept separate from our development and testing environments.

3. Signing in

Every sign-in needs both a password and a one-time code that we send to the account’s email address. Each code works once and expires after a short time, and repeated failed attempts are temporarily blocked.

Passwords are stored only as salted one-way hashes, never in a form that can be read back.

4. Access inside the marketplace

Each organisation sees only its own information and the information the marketplace is designed to share with it. Within an organisation, what each person can do depends on the role an administrator gives them.

The rule that bids are sealed is applied when the service retrieves data, not only in what its screens display, so an operator’s access is limited to its own bids.

5. Access by our team

Access to production systems and customer information is limited to the LastLook staff who need it to operate and support the service. A small number of authorised platform administrators can view the service as a particular user in order to provide support and investigate problems.

6. Credentials and secrets

API keys and invitation links are stored as one-way hashes, so they cannot be read back from our database. Application secrets are kept out of our source code.

7. Building and changing the service

Changes to the service go through code review and an automated test suite before they are released.

8. Monitoring and response

We monitor the service for errors and unusual behaviour using application monitoring tools, and we keep logs that help us investigate problems.

If we become aware of a security incident affecting your organisation’s information, we will investigate it, act to contain it, and notify you as the law and our agreements with you require.

9. Service providers

We use a small number of service providers for hosting, email delivery, monitoring and customer relationship management. They process information for us under written terms, and a current list is available on request to [email protected].

10. Your part

Security is shared. Keep your password and your email account secure, since sign-in codes are sent there, and never share a one-time code with anyone, including anyone who says they are from LastLook. We will never ask you for one.

Give each person their own account, grant only the access their role needs, and remove access promptly when someone leaves. Keep API keys secret, and think about who can see LastLook alerts wherever you send them.

11. Reporting a vulnerability

If you believe you have found a security vulnerability in LastLook, please email [email protected] with enough detail for us to reproduce it. We will acknowledge your report and keep you informed while we investigate.

Please act in good faith while researching: do not access, change or delete information that is not yours, do not degrade the service for others, do not use social engineering, phishing or physical attacks, and give us reasonable time to fix an issue before you disclose it. We do not currently offer payment for reports.

12. Changes to this page

We update this page as our practices change, and the date above always records the current version.

13. Contact

Security questions can be sent to [email protected].

© 2026 LastLook. All rights reserved.