Security
Last updated: August 24, 2026. This page says what we do, nothing more: no badge, no unverifiable promise.
What is in place
The whole site and app communicate over HTTPS. Data is hosted in the European Union (Google Cloud, Europe region), encrypted in transit and at rest. Production access is restricted to the two co-founders, and email delivery goes through contracted processors, listed in the privacy policy; the app's verification SMS go through Twilio, contracted too, detailed in the app's privacy policy published with it. The site sets no cookie and loads no external resource: there is no third party to compromise in your browser.
Reporting a vulnerability
Found a vulnerability, on the site or later in the app? Write to support@proofplaces.com with "Security" in the subject, a description, reproduction steps, and what you could observe. We acknowledge within 72 business hours, keep you posted on the fix, and credit you publicly if you wish. The security.txt file carries these coordinates in the standard format.
Good-faith rules
We will not pursue good-faith research that respects the following: do not access or exfiltrate other people's data (demonstrate with your own account), do not degrade the service (no denial of service, no spam), do not exploit the flaw beyond demonstration, and give us a reasonable delay to fix before any publication. There is no monetary reward at this time, and we say so rather than let you guess.
Out of scope
Social engineering against people, physical attacks, automated scanner reports without demonstrated impact, and services operated by third parties (App Store, telecom operators), which have their own programmes.