Security approach
Annot8 uses layered technical and organizational safeguards appropriate to a multi-tenant feedback platform. This page describes current product controls without claiming a certification or guaranteeing that incidents are impossible.
Current product controls
- TLS-encrypted transport and secure-origin requirements for production service URLs
- Managed Clerk authentication, session verification, workspace roles, and server-side tenant authorization
- Explicit domain/environment allowlists and short-lived origin-validated tokens for public widget writes
- Verified Clerk and Polar webhook signatures and idempotent billing-event processing
- AES-256-GCM application-layer encryption for newly stored integration credentials, with authenticated key rotation
- Browser redaction of URL credentials, query strings, and fragments for captured diagnostic/Analytics URLs
- Consent-gated Analytics, minimized collection, and scheduled physical retention deletion
- Upload size/type limits, private managed storage URLs, iframe sandboxing, and restricted browser permissions
- Dependency pinning, production software-composition audits, secret-pattern checks, linting, type checking, and production builds
- Account export/deletion, project/workspace cascade deletion, and short-lived widget-session cleanup
Customer responsibilities
- Require strong authentication and promptly remove people who no longer need access.
- Use least-privilege workspace roles and third-party integration tokens.
- Restrict allowed domains and do not expose secret keys, tokens, or webhook URLs in public content.
- Configure consent, recording notices, retention, AI, Analytics, and public portals for the customer’s audience and jurisdiction.
- Avoid capturing sensitive fields/pages and promptly delete data that is no longer needed.
- Report suspected compromise and rotate affected credentials immediately.
Report a vulnerability
Email security@annot8.app with the affected URL/component, reproduction steps, impact, and safe supporting evidence. Do not access data beyond what is necessary, disrupt service, use social engineering, degrade availability, publish secrets/personal data, or publicly disclose an unresolved issue. We will acknowledge a good-faith report, investigate, and coordinate remediation/disclosure where practicable.
The machine-readable contact is available at /.well-known/security.txt. Security incidents involving customer data should also identify the affected workspace and a trusted callback contact.
Assurance status
Annot8 does not currently claim SOC 2, ISO 27001, PCI DSS, HIPAA, or another independent certification. Payment-card processing is handled by the merchant of record. Customers with assurance requirements should request current architecture, vendor, testing, incident, backup, and access-control information before purchase.
- security@annot8.app
- Website
- annot8.app