Legal
Security & Responsible Disclosure
Last updated 23 August 2026 · Ideabazi Ventures LLC
Your LinkedIn presence and your drafts are sensitive. These are the controls we operate today, described plainly — we do not claim certifications we have not completed.
Controls in place
- All traffic served over TLS; data encrypted at rest by our infrastructure provider.
- Row-level security on every application table, so users can only read and write their own records.
- Private storage buckets for avatars and post media, served through short-lived signed URLs.
- Platform tokens and service secrets held in an encrypted secret store, never in client code.
- Server-side authorisation on every AI, publishing and billing endpoint.
- Passwords hashed by our auth provider, with breached-password (HIBP) checks enabled.
What we do not claim
We are not currently SOC 2, ISO 27001, HIPAA or PCI certified. Card data is handled entirely by Stripe, a PCI Level 1 provider.
Reporting a vulnerability
Email support@ideabazi.com with steps to reproduce. We acknowledge reports within 3 business days and will keep you updated until resolution. Please avoid accessing other users' data, degrading the Service, or publicly disclosing before a fix is shipped.
Questions about this document?
Email support@ideabazi.com and we will respond within 5 business days.