Security
Last updated: [date]
⚠️ Template to complete. Fill in the [TO FILL IN] fields, then have this document reviewed by a lawyer before going into production. It does not constitute legal advice.
Encryption
- All traffic is encrypted in transit (HTTPS/TLS).
- Data at rest is encrypted by our hosting providers (database, object storage).
Authentication
Authentication is managed by Clerk (signed sessions, two-factor authentication support). We never store your passwords in plain text.
Payments
Payments are processed by Stripe, PCI-DSS Level 1 certified. Sceina never sees or stores your card numbers.
Data isolation
Projects, media, and renders are isolated per user. Every access to a resource verifies account ownership server-side.
Report a vulnerability
If you believe you have found a flaw, write to us at [security email]. We commit to responding within 72 hours and to not pursuing legal action against good-faith research.