Security
Last updated: 2026-07-23
How we protect your data
- Traffic is encrypted in transit (HTTPS/TLS). Integration connection secrets are encrypted at rest with AES-256-GCM; other data is stored unencrypted on an access-controlled, private-network database.
- Admin sessions use short-lived, rotating tokens; passwords (when used) are hashed, never stored in plaintext.
- Access is tenant-isolated — each community’s data is scoped to that community, and admin actions are recorded in a tamper-evident audit log.
- Payments are handled by Stripe and PayPal; we never see or store full card numbers.
Reporting a vulnerability
If you believe you’ve found a security issue, please email [email protected] with steps to reproduce. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly, and avoid accessing or modifying other users’ data, degrading the service, or running automated scans that generate significant load.
We’ll acknowledge your report, keep you updated on the fix, and we won’t pursue action against good-faith research that follows this policy. We don’t currently run a paid bug bounty, but we’re grateful for responsible disclosure.