Security and data practices

Every InfiniHash app is built on one shared platform layer, so the practices below hold for all of them. Each app's own /security page adds what is specific to its data.

Accounts and sessions

Requests and browsers

Uploads and evidence

Data location, retention and deletion

Responsible disclosure

If you find a vulnerability in any InfiniHash app, email [email protected] with "Security report" in the subject. We acknowledge within two business days, keep you informed while we fix it, and credit you if you want. Please do not access other people's data, and give us time to fix before publishing.

Per-app security pages

We produce evidence and records. We do not give legal, tax or audit advice, and we never claim that you or your organization is compliant with a standard.