encrypted everywhere, access logged, and a paper trail. what's in place today.
pre-launch posture. this is what's in place today, not what we plan. see the privacy page for how long content is kept. security@getscrub.dev
every connection is tls 1.3 only. older protocols are refused at the edge. hsts is on for every subdomain with a one-year max-age. certificates rotate on their own.
everything we store, including the messages kept for improvement work, is encrypted with aes-256-gcm. keys live in a managed kms and rotate on a schedule. how long content stays is set by the privacy page.
your api keys are hashed, never stored in the clear. our own credentials sit in a managed secret store with access logs, rotate automatically, and never go into source control. scanners block accidental leaks before they reach the repo.
we are not soc 2 certified today. the type ii audit window is planned for q4 2026. the report will be available under nda once it's done. gdpr and ccpa rights don't wait for the audit.
tell us before you tell the internet: security@getscrub.dev. encrypted reports welcome, pgp key on request. we acknowledge within 6 hours on business days, share a triage timeline within 72, credit you if you'd like, and don't pursue good-faith research that respects user data and uptime.