We take the security of your data seriously. Here's how we protect it.
Data in transit is encrypted using TLS 1.2+. We do not currently operate database-level encryption at rest.
Your data is isolated per account, enforced on the server for every read rather than hidden in the browser. Administrative access is limited to the company owner.
We run on a dedicated cloud server behind a TLS-terminating reverse proxy, with the database on a persistent volume. We do not offer a contractual uptime SLA.
Audit pipeline failures are recorded and alert us by email, including a distinct alert when failures cluster in a short window. We do not operate continuous 24/7 infrastructure monitoring.
Found a vulnerability? We welcome responsible disclosure. Contact us at security@uxauditpro.com and we will respond within 48 hours.
We support Google OAuth for secure, passwordless sign-in. We never store plaintext passwords. Session tokens are HTTP-only cookies with short expiration windows and are invalidated on logout.
Uploaded files and screenshots are stored inside your audit record in our database, not with a third-party storage provider, and are never shared with other users or third parties. They are read by our analysis pipeline and by you.
Screenshots captured or uploaded for an audit are automatically cleared from the audit record 45 days after it is created, by a job that runs daily. You can request earlier deletion by contacting support.
We do not store credit card or payment details on our servers. All payments are processed through PayPal's PCI-compliant infrastructure. We only store transaction IDs and plan status.
If you discover a security issue, please report it to us privately at security@uxauditpro.com before public disclosure. Please include a description of the vulnerability and steps to reproduce.
We commit to acknowledging your report within 48 hours and resolving confirmed critical issues within 7 days. We do not pursue legal action against researchers acting in good faith.