Trust

Security

Updated June 18, 2026

We treat submitted content, account access, and measurement records as systems that must earn trust. This page states the current posture without inventing a certification we do not have.

Baseline controls

Production traffic uses HTTPS. Authentication, payments, data storage, hosting, error monitoring, and model processing are delegated to established providers with access limited to the functions required to run the service. Application changes are version-controlled and production errors are monitored.

Our engineering target is OWASP ASVS 5.0 Level 1 for public web surfaces, with stronger review for authentication, payment, administrative, and content-processing paths. Meeting a target is not the same as passing an independent audit; we will publish that distinction plainly.

Report a vulnerability

Send a concise report to trentonmcnelly@gmail.com. Include the affected URL, steps to reproduce, likely impact, and any supporting evidence. Please do not access other people's data, degrade the service, or publish the issue before we have had a reasonable chance to investigate.

What we will do

We will acknowledge a good-faith report, investigate it, preserve relevant evidence, and communicate material risk honestly. Response time depends on severity and available evidence; this is a reporting channel, not a bug-bounty promise.