Our approach
We use layered controls appropriate to each product, including least-privilege access, environment-separated secrets, transport encryption, validation, auditability, dependency review, and automated tests. Controls evolve with product maturity and risk.
Your responsibilities
Use a unique strong password, keep devices and recovery channels secure, review account activity, and contact us promptly if you suspect compromise. Never send passwords, one-time codes, or private keys by email.
Report a vulnerability
Send a concise report to our contact email with the affected product, reproducible steps, and impact. Do not access other users’ data, disrupt service, use social engineering, or publish details before we have had a reasonable opportunity to investigate.
Contact
Questions about this document can be sent to hello@scaleuptech.org.