Security and data handling
What the software does to protect accounts and data, stated as it is implemented. Please do not upload confidential project data to the evaluation build.
Signing in
- Accounts are created by the administrator. There is no public sign-up.
- Three sign-in methods, chosen per account: a six-digit code by email (valid 10 minutes, 5 attempts), a sign-in link by email (valid 15 minutes), or a password the administrator issues, stored only as a hash.
- You cannot change your own email or password; the administrator replaces either.
- Requests for codes and links answer the same way whether or not an address has an account, and are rate limited.
Sessions
- Sessions are held in HttpOnly, Secure cookies on app.foundanz.com only.
- On the server, an access token lasts 60 minutes. A sign-in session lasts 14 days from its last renewal and is replaced each time it is used.
- Your browser also signs you out after 12 hours without a keystroke, click or touch. That timer runs in the browser; the server does not enforce it.
- Your access period is checked on every request, so withdrawn access takes effect immediately.
Your projects
- Projects are private to your account.
- An administrator can open a project read-only to answer a support question, and every such opening is recorded in an audit log.
- A deleted project can be restored for 30 days, then is removed permanently.
Hosting and storage
- Vercel hosts this site and runs the application. Its functions run in Tokyo (hnd1).
- Supabase holds the database and file storage. Region: ap-northeast-1.
- Render runs the PDF renderer in Singapore. When a PDF report is produced, the report’s content is sent there to be laid out, and the PDF is sent back.
- Resend sends the application’s email: sign-in codes and links, account notices, and, to the administrator, feedback and access requests.
- Source documents for validation cases are kept in a private storage bucket of their own, served only through the application.
- Feedback screenshots and project thumbnails are kept in a separate bucket, at addresses that cannot be guessed. Anyone given such an address can open the image.
- Storage and database keys are held on the server and never sent to the browser.
- The Anthropic API key is held on the server and used only by the administrator’s step that drafts a validation case from an uploaded worked example. No project data is sent to it.
Reporting a problem
Write to info@foundanz.com with “Security” in the subject.