Independently Verified
Security and Trust
Security at ChamsPilot is engineered, not bolted on. This page documents the controls protecting your account, your money, and your creator/brand relationships, in plain English, with no marketing fluff.
- Encrypted At Rest: Industry-standard authenticated encryption
- Bcrypt + 2FA: Cost-tuned hashing + TOTP MFA
- Rotating Tokens: Reuse-detection refresh tokens
- GDPR Article 15/17: Self-serve export and delete
Posture last reviewed: April 26, 2026 · Continuously updated
Verified & Secured by TAC Security ESOF
ChamsPilot has completed an independent security assessment (Google CASA - Cloud Application Security Assessment), verified through the TAC Security ESOF platform by an authorized ADA CASA assessor.
Overview
ChamsPilot handles three things attackers love: money (creator payouts, brand budgets), third-party credentials (Gmail / Outlook OAuth, SMTP passwords), and contracts (legally binding signatures). We treat each one with the seriousness it deserves. The sections below describe exactly what is running in production, not what is on a slide deck.
- Defence in depth
- Least privilege
- Short blast radius
- Auditable
- Bcrypt+2FA: Cost-tuned hashing with TOTP-based two-factor
- 30 min: Short-lived access tokens with rotating refresh
- Strict: Per-IP API rate limits and login lockouts on abuse
- 24h: Auto-pause window if outbound patterns look abnormal
Identity and Authentication
Authentication is cookie-based. JWT access tokens never touch localStorage, eliminating the entire class of XSS-driven token theft.
- Password hashing: bcrypt with a cost factor tuned to make brute force computationally expensive.
- Password policy (NIST 800-63B): minimum 10 chars, 3-of-4 character classes, top-100 dumped-password block-list, keyboard-run detector, repeating-char detector, cannot contain your email local-part or 4+ char tokens from your name. HaveIBeenPwned k-anonymity check on every signup and password change.
- 2FA: Time-based One-Time Password (TOTP, RFC 6238) via any authenticator app. One-time backup codes for recovery.
- Access tokens: short-lived signed JWT delivered as HttpOnly; Secure; SameSite=Lax cookie.
- Refresh tokens: rotating tokens · each refresh issues a brand-new token and invalidates the previous one.
- Reuse detection: if an old refresh token is replayed (i.e., the attacker stole it), the entire token family is wiped server-side, forcing both legitimate user and attacker out, and a high-severity alert fires.
- Brute-force protection: repeated failed logins trigger a temporary account lockout. Abnormal failure spikes from a single IP trigger anomaly alerts.
- Passkey support: WebAuthn / FIDO2 hardware-backed passkeys for phishing-resistant login.
- Trusted devices: short-window device trust with IP binding for streamlined re-authentication.
Encryption
In transit: TLS 1.3 enforced everywhere. HSTS preload with long max-age and full subdomain coverage.
At rest: Sensitive third-party credentials are sealed with industry-standard authenticated encryption before they ever reach the database. Decryption only happens at the moment of use, in memory.
Versioned envelope: sealed blobs carry a version prefix so we can rotate algorithms without breaking the back-catalogue.
Storage: Database volumes are AES-256 encrypted at the storage layer. Backups inherit the same encryption.
- Gmail OAuth tokens: access_token + refresh_token sealed before storage
- Outlook OAuth tokens: access_token + refresh_token sealed before storage
- Google Calendar tokens: Read-only · sealed identical to mail tokens
- SMTP passwords: Per-user inbox connection passwords sealed at write
Application Security
- Global rate limiting: aggressive per-(auth user OR IP) caps on every /api/* route. Returns 429 with a Retry-After hint when exceeded.
- Per-route limits: stricter caps on login, registration, password reset, AI generation, and public-link guest endpoints.
- IDOR audit complete: every multi-tenant query is filtered by (resource_id, user_id). Cross-tenant leaks were patched in outreach sequences, contracts, briefs, and linked-creator endpoints.
- PII redaction in logs: emails, JWTs, Authorization headers, card-shaped numbers, and phone numbers are scrubbed at the logger layer before they hit disk.
- Security headers: Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy strict-origin-when-cross-origin, Permissions-Policy locking down camera / microphone / geolocation / payment.
- File upload hardening: extension blacklist, MIME whitelist, magic-byte inspection (rejects PE/ELF/Mach-O/shebang/HTML/PHP), filename sanitization, sandboxed download responses for non-media types.
- Webhook signature verification: Stripe webhooks hard-fail when their signing secret is unset · production cannot accept unsigned events.
- Signature integrity: contract signatures are size-validated client and server side · 1x1 transparent placeholder PNGs and empty payloads are rejected.
Threat Detection and Monitoring
An anomaly-detection job runs continuously. Alerts are de-duplicated and routed to our security ops inbox. Alert payloads contain SHA256-hashed user identifiers · the alert table itself stays PII-free.
Admin audit trail: every privileged action (impersonation, plan change, credit grant, password reset) is written to an immutable admin_audit_log with actor IP and user agent.
- Credential stuffing: Repeated failed logins targeting a single email
- IP-level brute force: Abnormal failure spikes from a single IP
- Lockout storms: Bursts of account lockouts in a short window
- Unusual send volume: Abnormal outbound patterns across users
- Refresh token reuse: Replay of a rotated refresh token
- Bounce-rate spikes: Auto-pauses sender when above safe thresholds
Email and Deliverability Security
- Plan-aware daily outbound caps: prevent compromised accounts from being weaponized as spam relays.
- Bounce circuit breaker: auto-pauses an autopilot for 24 hours when bounce rates cross safe thresholds.
- Authentication: SPF, DKIM, and DMARC alignment validated for every connected domain.
- OAuth scopes: we request scopes appropriate to the features you enable (e.g. mailbox read, send-as, calendar read).
- Body handling: email content is processed to power the features you've enabled; metadata and limited content may be cached subject to our retention schedule.
Data Protection and GDPR
ChamsPilot is built with GDPR principles in mind. The endpoints below are live.
- Sub-processors: Stripe handles payments. ELDIN AI powers all AI features (ephemeral inference, never used to train any model). Hosting runs on enterprise-grade EU and US infrastructure. Outbound email is delivered through reputable email infrastructure. External sub-processors are engaged under appropriate data processing terms.
- Data residency: primary infrastructure in EU and US regions. Cross-border transfers, where they occur, rely on appropriate transfer mechanisms (e.g. standard contractual clauses).
- Retention: indicative retention windows · approximately 90 days post-account-closure for personal data, up to 7 years for financial records, and up to 12 months for security logs. Specific periods may vary based on legal obligations.
- No sale of personal data: we do not sell personal data in exchange for monetary consideration. Where applicable law uses a broader definition of 'sale' or 'sharing', we will honour opt-outs as required.
- AI training: we do not provide your content to AI providers for the purpose of training their foundation models.
- GET /api/gdpr/export: Article 15 · returns your full record: profile, briefs, scripts, invoices, contacts, sequences, payments, and both sides of every deal you are party to. Tokens, password hashes, and 2FA secrets are stripped.
- POST /api/gdpr/delete: Article 17 · requires the confirmation phrase DELETE MY ACCOUNT. Anonymizes your user record (preserves _id for FK integrity), hard-deletes personal artifacts, wipes refresh tokens and connected integrations, and writes a security audit entry.
Key Management
- Master encryption key: stored only in our production secrets store. Never committed to git, never logged.
- Rotation procedure: a dedicated key-rotation tool decrypts each sealed blob with the previous key and re-seals it with the new one. The procedure is idempotent and dry-runnable.
- JWT signing key: separate from the encryption-at-rest key. Rotation invalidates active sessions cleanly.
- Production secrets: a pluggable secrets provider abstracts our enterprise secrets manager behind a single boot-time hydration call. .env remains the path for local development · production pods hydrate os.environ from the configured provider on startup.
Incident Response
If we detect or are notified of a security incident:
Backups: daily encrypted database snapshots with 30-day retention. Restoration tested quarterly.
Disaster recovery RPO: 24 hours. RTO: 4 hours.
- < 1 hour: Triage, scope, and contain
- < 24 hours: Notify any user whose data was at risk
- < 72 hours: Regulator notification when required (GDPR Art. 33)
Vulnerability Disclosure
We welcome security research. If you have found something, please tell us before telling anyone else.
Safe-harbour for good-faith research:
Report findings to [email protected]. For sensitive reports, request our PGP key in your initial email and we will reply with the fingerprint.
Acknowledgement within 48 hours, severity classification within 5 business days, fix timeline communicated based on severity. Hall of Fame credit available on request.
- Test only against accounts you own or have explicit permission to test.
- No DoS, no spam, no social engineering of our staff or users.
- Do not access, modify, or destroy other users data.
- Give us a reasonable window (typically 90 days) before public disclosure.
Trust Boundaries and Data Flow
ChamsPilot is organized into four trust zones, each enforcing its own controls:
Primary data flow: a request travels from the browser to the CDN, into the single-page app, then to the authenticated API, and finally to the database. Outbound integrations use per-user OAuth tokens that are encrypted at rest and sent only over TLS; AI features are powered by Eldin, our own AI.
- Public internet to CDN edge: a managed WAF, TLS 1.3 termination, OCSP stapling, and DDoS and rate-limit protection.
- Edge to web tier: the application is served behind a strict Content-Security-Policy, HSTS, and hardened response headers.
- Web tier to application tier: every API route is authenticated with short-lived JWTs and validated by injection guards and schema validation.
- Application tier to database: the database requires authentication and is reachable only on a private internal network, with no public port.
Data Classification and Protection Levels
All data is classified, and each class carries defined protection requirements:
Across every class we apply TLS 1.3 in transit, AES-256 encrypted backups at rest with a 14-day retention window, and least-privilege access.
- Secrets and credentials: (OAuth tokens, API keys): encrypted at rest with authenticated AES-256 encryption, TLS in transit, never written to logs.
- Personal data: (names, email addresses, profiles): owner-scoped access control, included in encrypted backups, and covered by GDPR export and delete rights.
- Business data: (deals, contracts, messages): protected by owner and team role-based access control.
- Operational and analytics data: non-sensitive and aggregate.
Access and Audit Logging
Security-relevant activity is recorded so authorized administrators can detect and investigate misuse, without ever storing the sensitive values themselves.
Access logs are retained in line with our data-protection obligations and are available to authorized administrators only.
- Administrative actions: are written to a dedicated audit trail with actor, action, timestamp, and source IP.
- Authentication and session events: (logins, trusted devices, anomalies) are logged for review.
- Sensitive values are never logged: passwords and session tokens are stored only in hashed or irreversible form, and payment details are never written to logs.
Compliance Roadmap
Where we are today and where we are going.
Enterprise prospects: a Vendor Security Questionnaire (VSQ) and our latest sub-processor list are available under NDA · email [email protected].
- Live: CASA (Cloud Application Security Assessment) - independent OWASP ASVS-aligned review passed
- Live: GDPR Article 15 (export) and Article 17 (delete) endpoints
- Live: CCPA-aligned data handling and opt-out
- Live: PCI scope reduction · card data handled exclusively by Stripe
- In progress: SOC 2 Type II audit kickoff
- Planned: ISO 27001 certification (post-SOC 2)
- Planned: Penetration test report (annual, available under NDA)
Get started free
ChamsPilot home
Read in another language: 简体中文 繁體中文 Français Español العربية