Encryption in transit and at rest
All traffic is served over TLS 1.3 with HSTS. Stored account data is encrypted at rest by the managed platform.
Security
A statement of the practices we operate today. We describe what we do, not what we aspire to, and we will not claim a certification we have not completed.
The controls behind every BMT session.
All traffic is served over TLS 1.3 with HSTS. Stored account data is encrypted at rest by the managed platform.
Internal access to production data is role-scoped, reviewed, and logged. No shared credentials.
A strict content policy, no inline third-party trackers before consent, and no personal data written to local storage beyond your own device preferences.
Every deployment is reviewed and reversible, with an audit trail from change to release.
We welcome good-faith research and we will not pursue researchers who follow this policy.
Account and data questions belong on the privacy policy page, and general enquiries on contact.