Skip to content
dotstrap
SECURITY

WHAT PROTECTS YOUR DATA, AND WHAT DOES NOT YET.

Everything below is how Dotstrap is actually built, not how we would like it to sound. The second half is the part most security pages leave out.

WHAT IS NOT IN PLACE YET

A security page listing only strengths tells you nothing, because every security page lists only strengths. These are the gaps we would want to know about if we were deciding whether to trust someone else with this.

  • No third-party security audit or penetration test has been completed, and Dotstrap holds no SOC 2, ISO 27001 or comparable certification. We will say so here on the day that changes, and not before.
  • There is no session or device management screen. You cannot currently see or revoke other signed-in sessions from inside the product; signing out of your Google account is the way to end access.
  • There is no two-factor authentication in Dotstrap itself. Your account is exactly as well protected as the Google account behind it, so enable Google's own 2-step verification.
  • Deletion runs when an account is next touched rather than on a scheduled sweep. An account nobody opens again is inert from the moment it is marked — nothing is served, nothing is matched — but its records may sit unpurged past the 30 days until something reaches them.
  • Model providers are third parties operating under their own terms. We route only to providers eligible for the region's residency rule and degrade rather than send data elsewhere, but we cannot audit their infrastructure for you.

Found something, or have a security or compliance question? Tell us through the Help screen inside Dotstrap, or the contact form on this site. We are a small team and would rather give you a direct, honest answer than a marketing one — and we would much rather hear about a vulnerability from you than from somebody else.

Take the address. Decide about the desk later.

It is free, it is yours permanently, and it cannot be changed afterwards.