← Legal & Privacy
Security & Data Protection Overview
Pre-launch version 0.9 · Last updated 29 August 2026. This page distinguishes verified controls from production controls that still require technical confirmation.
Verified in the currently reviewed website
- No live API keys are committed in the reviewed static website; Paddle configuration values are placeholders.
- Paddle checkout is sandbox/scaffolded and does not unlock paid access client-side.
- The checkout return page is informational; no client-side entitlement mutation is verified.
- No GA4, Sentry, advertising analytics or Bilveo cookie-setting code was found in the reviewed static site.
Production controls to verify before advertising them as implemented
- HTTPS-only production endpoints and secure transport.
- Server-side storage of API/provider secrets.
- Server-authoritative subscription entitlement after verified Paddle webhook processing.
- Authentication-token lifecycle, expiration and revocation controls.
- Appropriate CORS, CSP and security headers.
- Rate limiting and abuse controls on public/authenticated APIs.
- Input validation, bounded payloads and data-minimised AI requests.
- Least-privilege production access and environment separation.
- Security logging with defined retention and restricted access.
- Account/data deletion procedures spanning all relevant stores and processors.
Reporting
Security or privacy concerns may be reported to bilveo@QuadroHub.com. A dedicated security contact may be introduced when operational scale requires it.