DataStorified
Legal & Trust

Security Policy

Our security approach, local-storage model, file handling, and responsible disclosure process.

Effective: 29 June 2026Updated: 29 June 2026
Table of contents
This document is provided as a platform policy template and should be reviewed by qualified legal counsel before relying on it as legal advice.

1. Security overview

DataStorified uses a client-first design and managed hosting to reduce the server-side data footprint. Security is an ongoing risk-management process, not a guarantee that incidents cannot occur.

2. Data protection

We minimize collection, restrict access, use reputable providers, review dependencies, separate environments where appropriate, and retain server data only for defined operational or legal purposes.

3. Local storage security

Browser local storage is not encrypted by DataStorified and is accessible within the same browser profile. Protect your device, avoid shared sessions, and clear site data before transferring or disposing of a device.

4. Account security

If accounts launch, users will be responsible for strong credentials and device access. We intend to support secure session management, rate limiting, recovery controls, and stronger authentication where risk warrants it.

5. Encryption

Production traffic uses HTTPS through managed infrastructure. Future sensitive server-side records should use provider-supported encryption at rest and narrowly scoped secret management.

6. File handling

Current file tools do not process uploads. Future tools will prefer in-browser processing and will clearly state when remote processing, temporary storage, limits, and deletion schedules apply.

7. Responsible disclosure

Researchers should test only systems they own or have permission to assess, avoid privacy violations and disruption, use minimal proof, keep findings confidential while remediation is underway, and report promptly.

8. Vulnerability reporting

Send reports to security@datastorified.com with the affected URL, reproduction steps, impact, supporting evidence, and safe contact details. Do not include live credentials or exploit unrelated accounts.

9. Security limitations

We cannot guarantee rewards, response timelines, or safe harbor for destructive, extortionate, illegal, privacy-invasive, social-engineering, denial-of-service, or third-party testing. Good-faith reports will be assessed reasonably.

10. Contact security team

Security reports: security@datastorified.com. General privacy matters should go to privacy@datastorified.com so urgent vulnerability reports remain visible.

Legal contact

Questions about this document may be sent to legal@datastorified.com.