Security & GDPR Compliance

Last updated: September 2026

1. Data Encryption Standards

All tenant data stored in Google Datastore / Cloud NDB is encrypted at rest using AES-256 standards. All external traffic communicating with our APIs, redirects, and web frontend is enforced over TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.

2. Link Protection & Cryptographic Hashing

Protected links utilize server-side password gates. Passwords are never stored in plaintext — they are salted and hashed using modern bcrypt/Argon2 algorithms before being stored. Secret keys and tokens are securely managed via Google Secret Manager.

3. Multi-Tenant Isolation

Tenant data is rigorously partitioned by Organization UID across all datastore models, cache partitions, and Cloud Tasks queues. Automated middleware and query-level scoping prevent any cross-tenant data leakage.

4. GDPR & CCPA Rights

We practice data minimization and provide automated tools for data export, anonymization, and account termination upon request.