Last updated September 2026
Security
How customer data is protected. This page describes what is actually implemented.
1. Authentication
Email and password, with email confirmation required and sessions issued and refreshed by our managed authentication service.
2. Database access
Every table containing customer data enforces owner-scoped row-level security policies at the database layer, not just in application code.
3. Privileged operations
Scan execution, report assembly and PDF generation run in server-side jobs; privileged credentials are never exposed to the browser.
4. Files
PDFs are stored in a private bucket and served only through short-lived signed URLs.
5. Transport and encryption
All requests are served over HTTPS. Database contents and stored files are encrypted at rest by the managed platform.
6. Audit trail
Consent, deletion and billing events are recorded to a server-only audit table.
7. Reporting a vulnerability
Please contact us via the Contact page with reproduction steps before any public disclosure.
MySelfIdentity is a self-audit tool. It produces no reputation, risk, trust or character score, and must never be used for employment, tenancy, credit, insurance, education or any other eligibility decision.