Legal
Security & Disclosure.
Security is foundational to a platform that holds business data. Here's how we protect it, and how to reach us if you find a problem.
Last updated July 26, 2026
How we protect your data
- Encryption in transit — all traffic is served over TLS/HTTPS.
- Encryption at rest — data is stored in a managed PostgreSQL database encrypted at rest; connected-integration tokens are additionally encrypted with AES-256-GCM.
- Password protection — passwords are hashed with bcrypt and never stored in plain text.
- Session security — we use short-lived access tokens with rotating refresh tokens, so a leaked token has a limited lifetime.
- No card data on our servers — payments are handled by Stripe; we never see or store full card numbers.
- Abuse controls — rate limiting, usage metering, and per-provider budget limits guard against runaway or malicious use.
Reporting a vulnerability
If you believe you've found a security issue, please tell us privately at contact@westhillsai.agency with enough detail to reproduce it. We welcome good-faith reports and will acknowledge yours as quickly as we can.
Please do
- Give us a reasonable chance to investigate and fix the issue before disclosing it publicly.
- Report as soon as you can after discovery, with clear steps to reproduce.
- Only interact with accounts and data you own or have explicit permission to test.
Please don't
- Access, modify, or delete data that isn't yours, or degrade the service for others.
- Run denial-of-service tests, spam, or social-engineering attacks against our team or users.
- Publicly disclose the issue before we've had a chance to address it.
Good-faith safe harbor
If you make a good-faith effort to follow this policy, we'll treat your research as authorized, won't pursue legal action against you for it, and will work with you on a coordinated fix. We may recognize significant reports at our discretion.
Contact
Reach the security team at contact@westhillsai.agency.