Legal document
Security Policy
Security principles and operational controls for dnoise platform.
Contents
Section 1
Data Protection
- Encryption in transit: TLS 1.2 or higher.
- Encryption at rest: AES-256 for all stored data.
- OAuth tokens: stored encrypted, never in plaintext, never logged in cleartext.
- dnoise never receives or stores Stripe login credentials.
Section 2
Access Control
- Production system access restricted to authorized personnel only.
- Multi-factor authentication required for all production access.
- Role-based, least-privilege access controls.
- All production data access logged and reviewed.
Section 3
Vulnerability Management
Regular internal security audits and continuous vulnerability assessments. To report a vulnerability: admin@dnoise.online. Acknowledgement within 72 hours.
Section 4
Breach Notification
- Relevant supervisory authorities notified within 72 hours where required by applicable law.
- Affected Users notified without undue delay after breach is confirmed and assessed.
- Full incident documentation maintained.
Section 5
What dnoise Cannot Access
- Raw card numbers, CVV, or full PAN — Stripe API does not expose these.
- Stripe account login credentials.
- Data outside the approved read-only OAuth scope.
Legal questions
admin@dnoise.online
Privacy & data requests
admin@dnoise.online
Security disclosures
admin@dnoise.online