Security

Last updated: [date]

⚠️ Template to complete. Fill in the [TO FILL IN] fields, then have this document reviewed by a lawyer before going into production. It does not constitute legal advice.

Encryption

  • All traffic is encrypted in transit (HTTPS/TLS).
  • Data at rest is encrypted by our hosting providers (database, object storage).

Authentication

Authentication is managed by Clerk (signed sessions, two-factor authentication support). We never store your passwords in plain text.

Payments

Payments are processed by Stripe, PCI-DSS Level 1 certified. Sceina never sees or stores your card numbers.

Data isolation

Projects, media, and renders are isolated per user. Every access to a resource verifies account ownership server-side.

Report a vulnerability

If you believe you have found a flaw, write to us at [security email]. We commit to responding within 72 hours and to not pursuing legal action against good-faith research.