Security
We design BrandOps so that speed never comes at the cost of control. Here is how we protect your data and our systems.
Security practices
HTTPS by default
All traffic is served over TLS 1.2+ through Vercel. Certificates are provisioned and renewed automatically.
Security headers
We enforce HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy on every response.
Server-side credentials
Provider API keys are read only by server-side code. They are never exposed to the browser or embedded in client bundles.
Review-first controls
No publish or send action runs without explicit human approval. Generation is separated from delivery by design.
What we do not claim yet
BrandOps is currently a single-operator workspace. We do not yet hold third-party security certifications such as SOC 2 or ISO 27001, although our architecture and practices move in that direction. We are transparent about our current boundaries so you can make an informed decision.
Specifically:
- We do not yet offer multi-user authentication or role-based access control.
- We do not yet provide a formal bug-bounty program, but we welcome responsible disclosure.
- We do not yet participate in the EU-US Data Privacy Framework.
Reporting an issue
If you discover a vulnerability in BrandOps, please report it responsibly. Include:
- A clear summary of the issue.
- Steps to reproduce or a proof of concept.
- The browser and operating system you used.
- Your assessment of severity, if possible.
We will acknowledge valid reports and work with you to resolve the issue quickly.
Report a security issue
Use the contact form and select the security topic. We will respond as quickly as we can.
Contact security