Skip to main content
VerbaCut
Policies and trust
Draft for launch review

Security

Current security boundaries, responsible reporting, and operational limitations for VerbaCut's hosted service.

Effective: Not yet effectiveOperator: VerbaCut operator (legal name pending)

Launch configuration incomplete. The legal operator, address, contact, and effective date must be provided through server environment settings and reviewed by qualified counsel before this policy is treated as effective.

1. Current architecture

The hosted service keeps OpenAI, Resend, Stripe, and storage credentials server-side rather than in browser code. It uses tenant ownership checks, short-lived signed media URLs, HTTPS, upload size and path validation, temporary worker directories, rate limits, structured redacted logs, private object storage, scheduled backups, and tested account/project deletion. Local mode keeps media on the computer running the service.

2. Scope and limitations

These controls are an operational baseline, not a certification. VerbaCut does not currently claim HIPAA, PCI DSS for direct card handling, SOC 2, ISO 27001, or another formal security certification. Privileged host access, backup encryption, monitoring contacts, and legal incident-notice procedures require ongoing operator management.

3. What not to send

Do not upload passwords, API keys, payment card numbers, government identifiers, health records, or other highly sensitive material unless the service expressly supports that data and provides the required safeguards. VerbaCut is not currently represented as compliant with HIPAA, PCI DSS for direct card handling, SOC 2, or another certification.

4. Report a vulnerability

Use Support with the Security category. Include the affected URL, reproduction steps, impact, and safe evidence. Do not access other users' data, disrupt service, extort, or publish exploitable details before the operator has had a reasonable chance to investigate. Use the Support form; a direct support email has not yet been configured.

5. Incident notices

If a security incident affects personal data, VerbaCut will investigate, contain, document, and notify customers or authorities when required by applicable law. This page will be updated with a dedicated security contact and safe-harbor terms before a public bug-bounty program is offered.

Questions

Use Support and choose the category that matches your request. Do not include passwords, API keys, payment-card information, or unnecessary sensitive media.