Skip to main content
Back to home

Security

Last updated: August 29, 2026

Security approach

Annot8 uses layered technical and organizational safeguards appropriate to a multi-tenant feedback platform. This page describes current product controls without claiming a certification or guaranteeing that incidents are impossible.

Current product controls

  • TLS-encrypted transport and secure-origin requirements for production service URLs
  • Managed Clerk authentication, session verification, workspace roles, and server-side tenant authorization
  • Explicit domain/environment allowlists and short-lived origin-validated tokens for public widget writes
  • Verified Clerk and Polar webhook signatures and idempotent billing-event processing
  • AES-256-GCM application-layer encryption for newly stored integration credentials, with authenticated key rotation
  • Browser redaction of URL credentials, query strings, and fragments for captured diagnostic/Analytics URLs
  • Consent-gated Analytics, minimized collection, and scheduled physical retention deletion
  • Upload size/type limits, private managed storage URLs, iframe sandboxing, and restricted browser permissions
  • Dependency pinning, production software-composition audits, secret-pattern checks, linting, type checking, and production builds
  • Account export/deletion, project/workspace cascade deletion, and short-lived widget-session cleanup

Customer responsibilities

  • Require strong authentication and promptly remove people who no longer need access.
  • Use least-privilege workspace roles and third-party integration tokens.
  • Restrict allowed domains and do not expose secret keys, tokens, or webhook URLs in public content.
  • Configure consent, recording notices, retention, AI, Analytics, and public portals for the customer’s audience and jurisdiction.
  • Avoid capturing sensitive fields/pages and promptly delete data that is no longer needed.
  • Report suspected compromise and rotate affected credentials immediately.

Report a vulnerability

Email security@annot8.app with the affected URL/component, reproduction steps, impact, and safe supporting evidence. Do not access data beyond what is necessary, disrupt service, use social engineering, degrade availability, publish secrets/personal data, or publicly disclose an unresolved issue. We will acknowledge a good-faith report, investigate, and coordinate remediation/disclosure where practicable.

The machine-readable contact is available at /.well-known/security.txt. Security incidents involving customer data should also identify the affected workspace and a trusted callback contact.

Assurance status

Annot8 does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent certification. Payment-card processing is handled by the merchant of record. Customers with assurance requirements should request current architecture, vendor, testing, incident, backup, and access-control information before purchase.