Security

Your data,
handled with care.

What we do to protect your account, your product descriptions and your classification history. And what we do not claim to do yet.

No certification badge: we do not hold any.

Current state
Traffic encryption
HTTPS / TLS
Account access
Authentication required
Public forms
reCAPTCHA
Non-essential cookies
After consent
Certifications
None
The measures

What is in place,
today.

Nothing beyond what our legal pages already describe.

Encrypted in transit

All traffic runs over HTTPS/TLS, pages and API alike: neither your credentials nor your product descriptions travel across the network in the clear.

Restricted access

Every session requires authentication, and access to production data is limited to the people who need it to run the service.

Abuse protection

Public forms and account creation go through reCAPTCHA, to keep bots and bulk submissions at a distance.

Cookies under control

No non-essential cookie is set before you agree, and your choice stays changeable from the banner at any time.

Declared providers

The third parties involved in processing your data - hosting, email, AI models - are described in the privacy policy.

Deletion on request

Access, correction, deletion: the steps are documented, and an email is enough to start the process.

In practice
01

HTTPS on every page and every API call

02

No non-essential cookie before you agree

03

Access, correction and deletion: the steps are documented

04

The providers that process your data are described in the privacy policy

What we do not claim

A badge is quick to display. Here is what we do not have, and what you will therefore not see on this page.

  • No certification: neither SOC 2, nor ISO 27001, nor HIPAA
  • No external security audit published to date
  • The product is under active development: avoid sending particularly sensitive information
Responsible disclosure

Think you found
a vulnerability?

Email us with the steps to reproduce it. We acknowledge every report, and we do not pursue anyone reporting in good faith.

contact@transinaut.com
  1. 01

    Send the details by email: the steps, the URL concerned and the impact you estimate.

  2. 02

    We acknowledge receipt and tell you whether we can reproduce the problem.

  3. 03

    We fix it, then confirm the fix to you once it is live.

  4. 04

    We credit you publicly if you want us to.

Please do not test on accounts that are not yours, and do nothing that degrades the service for other users.

Frequent questions

The questions
we get asked.