1. Current application controls
Passwords are salted and hashed; session tokens are stored as digests; account data and report access are owner-scoped; guest identifiers separate temporary sessions; uploads use generated storage names, extension allowlists, byte limits and video decoding checks; sensitive responses disable caching; and security headers restrict framing, content types, browser permissions and content sources.
2. Payments
Card details are handled by configured Stripe-hosted checkout rather than stored by WarriorIQ. Stripe webhook signatures are verified and event identifiers are processed idempotently.
3. Responsible disclosure
Send a concise vulnerability report to the configured support address, including reproduction steps and impact. Do not access other users' data, disrupt service or publish exploitable details before the operator has had a reasonable opportunity to investigate.
4. Production obligations
A public operator still needs managed secrets, encrypted backups, access logging, patching, rate limits, malware scanning, incident response, vendor review, tested restoration and jurisdiction-appropriate breach procedures. Launch readiness does not claim those operational tasks are complete.
5. Contact and operator
Verified operator, jurisdiction, and monitored support details will be published here before paid public launch.