Security

Security at Stredy

How we protect accounts, product files, integrations, and the generation pipeline.

Last reviewed: 5 September 2026

Security principles

  • Least-privilege access to production systems and connected services.
  • Encrypted HTTPS connections for web traffic.
  • Secrets kept outside source code and rotated when exposure is suspected.
  • Scoped marketplace tokens and revocation when a connection is removed.
  • Validation and machine checks before generated files are delivered.
  • Logging, rate limits, and operational monitoring for abuse and reliability.
  • Backups and recovery procedures tested against documented objectives.

Shared responsibility

Use a unique password or secure sign-in method, protect your email account, review connected stores, remove access you no longer need, and never share credentials in a product brief. Review every output before publishing.

Report a vulnerability

Use the security route on the contact page with the affected URL, impact, reproduction steps, and supporting evidence. Do not access other users’ data, disrupt service, use social engineering, or publish a vulnerability before we have had a reasonable opportunity to investigate. We will acknowledge credible reports and coordinate remediation.

Security claims

This page describes intended and operating practices, not a certification. Do not add claims such as SOC 2, ISO 27001, HIPAA, PCI DSS, penetration-tested, or end-to-end encrypted unless current evidence supports them.