Security

How we protect your data and how to report security vulnerabilities.

Our security practices

Encryption in transit and at rest

All data transmitted between your browser and Assembr is encrypted using TLS 1.3. Data stored on our servers is encrypted at rest using AES-256.

OAuth — no password storage

Assembr uses each platform's OAuth 2.0 — we never see or store your passwords. OAuth tokens from LinkedIn and all future integrations are stored encrypted and rotated regularly.

Infrastructure in Germany

Our servers are located in Germany (Berlin region), subject to GDPR and German data protection law. [Hosting provider: Hetzner — Placeholder, confirm before launch].

Principle of minimal access

Assembr requests only the API scopes strictly required per platform to display your analytics and schedule your content. For LinkedIn specifically, we do not request write access beyond post scheduling. Scopes are reviewed and minimized for each platform integration.

Responsible disclosure

If you discover a security vulnerability in Assembr, we ask that you disclose it to us responsibly. Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and address it.

We commit to acknowledging your report within 72 hours and providing a resolution timeline within 14 days for critical issues.

Report a security issue

Please include: a description of the vulnerability, steps to reproduce, affected component, and your contact information.

security@kaxtus.com

PGP key available on request. [Key fingerprint placeholder — TBD]

Bug bounty

Assembr does not currently operate a formal bug bounty program. We appreciate responsible disclosure and will publicly acknowledge researchers who report valid vulnerabilities (with their permission). [Bug bounty program placeholder — may be introduced post-launch].