Security

What AttestProof does to protect accounts, imported rows, reviewer links and evidence packs, and what data it holds, stated plainly.

Accounts

Tenancy

Every table that holds customer data carries the account id, and every query filters by it. Object ids are random and unguessable, but access never relies on that: a request for another account's object returns "not found".

Imported files and reviewer links

Evidence packs and the hash chain

What data is held, and for how long

Transport and browser

Operations

Reporting a problem

If you believe you have found a security issue, email [email protected] with "security" in the subject. We acknowledge reports within two business days and do not pursue researchers who act in good faith.