Security and data handling
A plain-language summary of how BriefCraft protects your account, your payments and the data we process. We don't claim certifications we don't hold.
Accounts and sessions
- Passwords are hashed with bcrypt; we never store or see them in plain text.
- Sessions use signed tokens in HttpOnly, SameSite cookies, sent only over HTTPS in production.
- Sign-in, sign-up and password-reset endpoints are rate-limited. Password reset links are single-use and expire after one hour.
- Google sign-in tokens are verified with Google on our server before an account is opened.
Payments
Payments are processed by Dodo Payments, which acts as Merchant of Record, with Airwallex as a payment partner. Card details are entered on their hosted checkout and never reach BriefCraft's servers. Subscription changes are applied only after a cryptographically signed webhook from Dodo Payments is verified.
API keys
Agency API keys are shown once when generated and stored only as a SHA-256 hash. Rotating a key immediately disables the previous one.
Crawler safety
Our crawler only requests public internet addresses. Requests to private, loopback, link-local and cloud-metadata addresses are blocked, and every redirect is re-checked before it is followed. The crawler identifies itself with the user agent BriefCraft-SiteAudit-Bot.
Data we process
We store your account details, audit history, Launch Package intake information and billing status. Audit results and product descriptions are processed by a third-party AI model provider to generate briefs and launch copy. See the Privacy Policy for the full list of processors and your rights.
Reporting a vulnerability
If you believe you have found a security issue, email [email protected] with the subject "Security report". Please give us reasonable time to fix the issue before disclosing it, and don't access other customers' data or degrade the service while testing. We'll acknowledge reports within two business days.