Trust & Email Security

This page is maintained by ComplyWise to answer common security and privacy questions about the ComplyWise Office Hours registration site (officehours.online). It describes current, app-visible controls. It is not an independent certification or audit.

Email authentication

Notification and confirmation emails are sent from notify.simonlinstead.com, a dedicated sending subdomain. The following email-authentication standards are configured on that subdomain:

  • SPF — only authorised servers may send mail using this domain.
  • DKIM — every message is cryptographically signed, so receiving servers can verify it was not altered in transit.
  • DMARC — published policy tells receivers how to handle messages that fail SPF or DKIM.
  • TLS — mail is delivered over encrypted connections wherever the receiving server supports it.

You can verify these records yourself with any public DNS lookup tool (for example mxtoolbox.com) by querying notify.simonlinstead.com.

Website security

  • The site is served over HTTPS with a valid TLS certificate.
  • The custom domain officehours.online is the canonical address — please share this link rather than any hosting-platform preview URL.
  • Registration data is transmitted over HTTPS and stored in a managed database with row-level security enabled.

What we collect & why

When you register interest we collect the name, work email, job role and phone number you submit. We use these details only to contact you about upcoming ComplyWise Office Hours sessions and related ComplyWise updates.

Reporting a security concern

If you believe a link claiming to be from ComplyWise Office Hours is suspicious, or you've received a warning when visiting this site, please email simon.linstead@complywise.online with the URL and a screenshot of the warning so we can investigate.

Last updated July 2026.