Security
Security
Last updated: August 2026
How we handle your data
Every problem you submit is treated as confidential. Access is limited to the specific human expert working on your project and studio operators who need it to deliver the work. We never sell, rent, or share your information with third parties for marketing purposes.Access control
Our team uses individual accounts with strong, unique passwords and two-factor authentication where supported. Employees only see the data required for their role. When a project ends, access to its materials is revoked.Code and delivery security
Deliverables are reviewed by a human before they reach you. Where a solution involves credentials or API keys, we follow environment-variable best practices and never hardcode secrets into source code. You receive full ownership of the code we build for you.Third-party services
We use a small set of trusted services (hosting, email, payments) to operate. Each one is vetted for its security posture, and we only send them the minimum data required for the task. A list of our key sub-processors is available on request.Encryption
Data in transit is protected with TLS on every page and API call. Attachments you upload are stored with restricted access and cleaned up per our retention policy.Responsible disclosure
If you believe you have found a security issue in our platform, we ask you to report it privately through the problem submission form rather than publicly. Include a clear description, reproduction steps, and impact. We acknowledge reports within 48 hours and work toward a fix promptly. We do not pursue legal action against researchers acting in good faith.Found a vulnerability?
We take responsible disclosure seriously. Submit a problem with the details and we'll respond within 48 hours.
Submit a problem