Security Policy
How HumanAIFusion protects your data — and how to report a security concern
Introduction
Our Commitment to Security
HumanAIFusion ("we", "our", or "us") takes the security of your data seriously. This Security Policy describes the technical and organizational measures we use to protect the information you entrust to us, and how to reach us if you discover a potential vulnerability.
Infrastructure Security
Where Our Services Run
Our website and applications are hosted on modern, managed cloud infrastructure. Application hosting is provided by Vercel, and our databases run on Supabase's managed PostgreSQL platform. Both providers maintain their own robust security programs, including physical data center security, network protections, and continuous monitoring.
Managed hosting
Application infrastructure managed and patched by our cloud providers
Bot protection
Cloudflare Turnstile challenges protect our sign-up, login, and contact forms from automated abuse
Network protections
Provider-level firewalls and DDoS mitigation guard our services
Data Encryption
Encryption in Transit and at Rest
All traffic between your browser and our services is encrypted using TLS (HTTPS). Data stored in our databases is encrypted at rest by our infrastructure providers.
What this means for you: Your information is protected both while it travels across the internet and while it is stored on our systems.
Access Control & Authentication
Who Can Access What
Access to customer data is restricted to what is necessary to operate and support our services.
- ✓User accounts are protected by a dedicated authentication service with secure session management.
- ✓Administrative functionality is restricted to authorized team members through role-based access controls.
- ✓Database access is governed by row-level security policies, so users can only reach data they are permitted to see.
- ✓Service credentials follow the principle of least privilege and are stored as protected environment secrets, never in source code.
Data Handling & Retention
How We Handle Your Data
We collect and process personal information only to deliver and improve our services. We do not sell your personal information. For full details on what we collect, why, and how long we keep it, please see our Privacy Policy.
Third-Party Services
Our Service Providers
We rely on a small set of reputable third-party providers for hosting, databases, customer relationship management, and communications. Each provider maintains its own security program, and we share only the data required for them to perform their function on our behalf.
Incident Response
If Something Goes Wrong
If we become aware of a security incident affecting your data, we will investigate promptly, take steps to contain and remediate the issue, and notify affected users and regulators as required by applicable law.
Reporting a Vulnerability
Responsible Disclosure
If you believe you have found a security vulnerability in our website or services, we appreciate your help in disclosing it to us responsibly. Please email us with a description of the issue and steps to reproduce it, and give us a reasonable opportunity to investigate and address it before any public disclosure.
Questions about this policy?
We're here to help. Reach out to our privacy team for any questions or concerns.