Security Policy

Encryption, access control, monitoring, resilience, and responsible disclosure practices.

Version
1.0
Status
Draft — pending legal review
Effective
2026-01-01
Reading time
2 min

Encryption

Data is encrypted in transit using current TLS and at rest by our infrastructure providers. Secrets are stored in managed secret storage, never in source code.

Access control

  • Multi-factor authentication is required for administrative access
  • Role-based permissions enforce least privilege, reviewed periodically
  • Strong password standards and session timeouts are enforced
  • Access is revoked promptly when a role changes or ends

Monitoring and audit logging

Authorization decisions, administrative actions, and security-relevant events are logged with actor, timestamp, and outcome, and reviewed on a scheduled cadence.

Resilience

Managed backups are taken on a regular schedule with point-in-time recovery, and restoration is periodically tested. Disaster recovery objectives are documented and reviewed annually.

Third-party integrations

Integrations are reviewed before enablement for data access scope, authentication model, and vendor security posture, per the Vendor Security Standards.

Responsible disclosure

Report suspected vulnerabilities to us with enough detail to reproduce. Do not access other users' data, degrade service, or publicly disclose before we have had a reasonable opportunity to remediate. We will not pursue action against good-faith researchers who follow this policy.

Changes to this document

We may update this document as our services, technology, and legal obligations evolve. Material changes are published with a new version number, an updated effective date, and a summary of changes in the version history below.

Continued use of our websites, products, services, experiences, or communities after an update takes effect constitutes acceptance of the current version.

Contact

Questions about this Security Policy may be sent to our legal and compliance contact through the contact form on this site. Please reference the document title and version number.

  • Legal & compliance requests: use the Contact Legal link on this page
  • Privacy and data rights requests: see the Consumer Privacy Rights policy
  • Accessibility accommodations: see the Accessibility Statement

Review notice

This document is a high-quality draft template prepared for review. It is not legal advice and no guarantee of compliance is made or implied. Final responsibility for legal sufficiency rests with the organization's licensed legal counsel.

Found a vulnerability?

We welcome responsible disclosure and will acknowledge every valid report.

Related policies