Trust & Safety

Security

We take the security of your data seriously. Here's how we protect it.

Data Encryption

Data in transit is encrypted using TLS 1.2+. We do not currently operate database-level encryption at rest.

Access Control

Your data is isolated per account, enforced on the server for every read rather than hidden in the browser. Administrative access is limited to the company owner.

Infrastructure

We run on a dedicated cloud server behind a TLS-terminating reverse proxy, with the database on a persistent volume. We do not offer a contractual uptime SLA.

Monitoring

Audit pipeline failures are recorded and alert us by email, including a distinct alert when failures cluster in a short window. We do not operate continuous 24/7 infrastructure monitoring.

Responsible Disclosure

Found a vulnerability? We welcome responsible disclosure. Contact us at security@uxauditpro.com and we will respond within 48 hours.

Authentication

We support Google OAuth for secure, passwordless sign-in. We never store plaintext passwords. Session tokens are HTTP-only cookies with short expiration windows and are invalidated on logout.

Uploaded Files

Uploaded files and screenshots are stored inside your audit record in our database, not with a third-party storage provider, and are never shared with other users or third parties. They are read by our analysis pipeline and by you.

Screenshots captured or uploaded for an audit are automatically cleared from the audit record 45 days after it is created, by a job that runs daily. You can request earlier deletion by contacting support.

Payment Security

We do not store credit card or payment details on our servers. All payments are processed through PayPal's PCI-compliant infrastructure. We only store transaction IDs and plan status.

Reporting a Vulnerability

If you discover a security issue, please report it to us privately at security@uxauditpro.com before public disclosure. Please include a description of the vulnerability and steps to reproduce.

We commit to acknowledging your report within 48 hours and resolving confirmed critical issues within 7 days. We do not pursue legal action against researchers acting in good faith.