Security

Security at misquoted.

We measure how accurately AI describes other people's brands. That means we have to take a stricter line on our own.

All systems operational
99.97% uptime · 90 days
SOC 2 Type II — in audit
Report expected Q3 2026
No incidents in last 12 months
Full history at status page
Trust pillars

Four things we get right.

Security isn't a checklist, but you have to start somewhere. These are the four areas where we hold the line, and the specifics behind each.

01 / Infrastructure
Cloudflare-native, U.S.-region.

Customer data lives on Cloudflare Workers, D1, and R2. Every request terminates at a regional edge with DDoS protection and WAF rules tuned for our threat model.

  • U.S.-region storage by default; EU-region available on enterprise plans
  • WAF blocks malformed scan payloads and credential-stuffing patterns
  • Automatic mTLS between worker and database tier
02 / Authentication
Passkeys, TOTP, no passwords.

There is no password to phish, leak, or reuse. Passkey authentication is the default. TOTP is supported as fallback. Recovery is device-based and rate-limited.

  • WebAuthn-backed passkeys on all accounts
  • TOTP via RFC 6238, 30-second drift window
  • Step-up auth required for billing and member changes
03 / Encryption
TLS 1.3 in transit, AES-256 at rest.

Every byte in and out is encrypted. Keys are rotated on a 90-day schedule. Database snapshots are encrypted independently and stored in a separate region.

  • TLS 1.3 only — TLS 1.2 disabled at the edge
  • AES-256-GCM for column-level secrets
  • HSTS preload-eligible, max-age 1 year
04 / Compliance
SOC 2 Type II, in audit.

We're mid-window on our SOC 2 Type II audit, with a Type I report available under NDA today. GDPR-aligned for EU customers; DPA available on request.

  • SOC 2 Type I — available under NDA
  • SOC 2 Type II — Q3 2026 expected
  • GDPR, UK-GDPR, CCPA aligned · DPA
Scan data, specifically

How we handle what we learn.

When you scan a domain, we generate a query set, send those queries to third-party AI models, and store the responses verbatim alongside the scores we derive. That bundle is the report. Without it, the report cannot exist.

The report is yours. It's encrypted at rest, scoped to your account, and exportable in full. We do not share it with other customers. We do not surface it on the public leaderboard unless you explicitly opt in.

For methodology improvement, we aggregate query patterns and scoring signals across all scans — never the raw responses, never anything identifiable. The aggregations stay inside the company.

We do not train AI models on your data. We are not in the foundation-model business and have no plans to be. If our policy on this ever changes, you'll see a 30-day notice email, and the change will be opt-in only.

!
Found a vulnerability? Tell us.

We run a responsible-disclosure program — no formal bug bounty yet, but we acknowledge every report within one business day and credit researchers in our hall of fame. PGP key on request.

security@misquoted.ai