Security & Vulnerability Disclosure
Last updated: 2026-07-26
How we protect your data
- All traffic encrypted in transit with TLS 1.2 or higher
- Data at rest encrypted with AES-256 in the underlying database and object storage
- Row-level security policies on every table — users only see data assigned to their role
- Password hashing via industry-standard adaptive algorithms (bcrypt/scrypt) handled by our identity provider
- Optional leaked-password check (HIBP) on signup and password change
- Payment card data is handled exclusively by Stripe under PCI DSS Level 1; we never see or store card numbers
- Administrative actions and document access are logged and audited
- 7-year retention on closed short-sale files, then automated deletion
- Backups retained by our infrastructure provider with encryption at rest
Responsible disclosure
We welcome reports from independent security researchers. If you discover a vulnerability, please report it privately to legal@shortsalegenie.com and give us a reasonable window to remediate before any public disclosure.
In your report, please include:
- A clear description of the vulnerability
- Steps to reproduce (URLs, payloads, screenshots)
- Potential impact
- Your contact information for follow-up
Safe-harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access data beyond what is needed to demonstrate the issue, and give us a reasonable window to fix the problem before public disclosure.
Breach notification
In the event of a confirmed personal-data breach affecting your account, we will notify affected users without undue delay and, where required by law, within 72 hours of confirming the incident.