Security & GDPR Compliance
Last updated: September 2026
1. Data Encryption Standards
All tenant data stored in Google Datastore / Cloud NDB is encrypted at rest using AES-256 standards. All external traffic communicating with our APIs, redirects, and web frontend is enforced over TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.
2. Link Protection & Cryptographic Hashing
Protected links utilize server-side password gates. Passwords are never stored in plaintext — they are salted and hashed using modern bcrypt/Argon2 algorithms before being stored. Secret keys and tokens are securely managed via Google Secret Manager.
3. Multi-Tenant Isolation
Tenant data is rigorously partitioned by Organization UID across all datastore models, cache partitions, and Cloud Tasks queues. Automated middleware and query-level scoping prevent any cross-tenant data leakage.
4. GDPR & CCPA Rights
We practice data minimization and provide automated tools for data export, anonymization, and account termination upon request.