Security

What is in place today, stated as facts about how the service is built.

Signing in

Sign-in is through Google only. StrandScribe never sees or stores a password. A session is kept in one cookie that scripts cannot read, and signing in again ends earlier sessions.

Your videos

A shared video is stored privately, read once, and deleted as soon as that is done, with a 24-hour limit as a backstop. It is never public and never shown to another user.

Your platform keys

A key you connect is checked with the platform, encrypted with AES-256-GCM under a key held separately from the database, bound to your account, and never shown again, not even to you. Disconnecting erases it.

Your data and other people

Every brief, source, draft, and setting is tied to one account and read only by it. Your Instagram sender identity is kept as a one-way hash. Nothing is public unless you post it or turn on a public page for an article.

Reading the web

Pages are fetched only from public https addresses, never from private networks, and text on a fetched page is treated as material to quote, not as instructions.

Hosting

The service runs on Cloudflare. Traffic is encrypted in transit.

Reporting a problem

If you find a security problem, write to hi@strandscribe.com with what you found and how to reproduce it. Please give us a chance to fix it before telling others.