1. Encryption in transit
Issued by Google Trust Services, valid until 12 December 2026, for metafenixgroup.com. Read directly from the certificate presented to your browser at the moment this page was generated, the same way our checker reads a firm's own certificate history. It is never asserted without being checked.
1.1 Every page on this site, and every page of the checker, is served only over HTTPS. An unencrypted request is never accepted.
1.2 The certificate is issued by a public certificate authority and logged in the public Certificate Transparency system, which anyone can search independently. Section 6 shows you how.
2. Account and session security
- Passwords are never stored in readable form. Each one is salted and hashed with PBKDF2-SHA256 at 600,000 iterations before it ever reaches our database.
- Your sign-in session is a randomly generated identifier held in a cookie marked HttpOnly and Secure, so it cannot be read by a script on the page or sent over an unencrypted connection, and it is revoked immediately on sign-out, a password change, or account deletion.
- A form submitted from any other website is refused. This is what stops a malicious page elsewhere from acting on your account without your knowledge.
- Repeated sign-in attempts from one address are rate limited, so a stolen password cannot be tried automatically at scale.
3. Assessment security
- Each assessment is opened with a single-use link, valid for a short window. Once it has been used, or the window has passed, it cannot be reused.
- A check is deducted from your account only at the moment the assessment actually runs, atomically, so a failed or abandoned attempt never costs you one.
- The website and the assessment engine authenticate to each other with a shared secret that is never sent to, or visible from, your browser.
- Your answers are held only for the duration of your session to produce the result. They are never written to our database; only the firm's name, the pathway, the verdict and the score are kept, in your verification history.
4. Payment security
4.1 MetaFenix Management Ltd holds a current, signed Attestation of Compliance against PCI DSS v4.0.1 (Self-Assessment Questionnaire D), assessed as fully compliant.
4.2 Card and bank details are never entered on this site, and never reach our servers at all. Payment on metafenixgroup.com is processed through Elavon's own hosted payment page: your card details are typed directly into Elavon's system, not ours, and we receive back only your order's reference and the amount paid. See our Payment and Refund Policy for exactly how a payment is confirmed.
5. Data handling
5.1 We collect as little personal data as we can to run this service, hold it for no longer than we need to, and never sell it or use it for advertising. The full detail, including retention periods and your rights, is in our Privacy Notice and Cookie Policy.
5.2 IP addresses used to limit repeated attempts are held in memory for no more than one hour, and only strictly necessary cookies are set: nothing tracks you between visits.
6. Verify it yourself
6.1 Every claim above is something you can check independently, not something you have to take on trust:
- The certificate: search
metafenixgroup.comat crt.sh, the public Certificate Transparency log search our own checker uses to verify other firms' websites. - Our ICO registration: reference ZC187194, searchable at ico.org.uk.
- Our company record: number 16921717, searchable at Companies House.
6.2 If you believe you have found a genuine security issue with this site, please tell us through our contact form before disclosing it anywhere else, so we can fix it.