WHAT PROTECTS YOUR DATA, AND WHAT DOES NOT YET.
Everything below is how Dotstrap is actually built, not how we would like it to sound. The second half is the part most security pages leave out.
SIGN-IN
Google only. Dotstrap never receives or stores a password, and never asks for a phone number. There is nothing in our database for an attacker to crack.
ENCRYPTION
Encrypted in transit everywhere. Conversations and other sensitive fields are encrypted again at rest, under keys scoped to a single region — a workload in one region cannot obtain another region's keys.
DATA RESIDENCY
Your account has a home region, fixed when it is created. Personal and sensitive data is written there and stays there. Intent Match will show you fewer people rather than match across a border.
PSEUDONYMOUS DELIVERY
When you write to someone, their region receives an opaque pseudonym, not your identity. Your name is resolved for display through a separate authorised call — it is never written into their records.
CLASSIFIED BY FIELD
Every field carries a data class, and the handling follows from the class rather than being decided again at each call site. Sensitive fields are never logged, never globally cached, and enter a model prompt only where the rule allows.
NO TRACKING, AT ALL
No analytics, no advertising, no pixels, no third-party measurement. One cookie keeps you signed in. Five values live in your own browser and are never sent to us.
SERVER-SIDE AUTHORISATION
Every request is authorised on the server, against the identity that made it. The interface never decides what you may see — it only draws what the server was willing to send.
DELETION THAT MEANS SOMETHING
A 30-day grace period, then your data is deleted and your address retired permanently. Conversations you had with other people are anonymised rather than destroyed — we do not reach into somebody else's mail.
WHAT IS NOT IN PLACE YET
A security page listing only strengths tells you nothing, because every security page lists only strengths. These are the gaps we would want to know about if we were deciding whether to trust someone else with this.
- No third-party security audit or penetration test has been completed, and Dotstrap holds no SOC 2, ISO 27001 or comparable certification. We will say so here on the day that changes, and not before.
- There is no session or device management screen. You cannot currently see or revoke other signed-in sessions from inside the product; signing out of your Google account is the way to end access.
- There is no two-factor authentication in Dotstrap itself. Your account is exactly as well protected as the Google account behind it, so enable Google's own 2-step verification.
- Deletion runs when an account is next touched rather than on a scheduled sweep. An account nobody opens again is inert from the moment it is marked — nothing is served, nothing is matched — but its records may sit unpurged past the 30 days until something reaches them.
- Model providers are third parties operating under their own terms. We route only to providers eligible for the region's residency rule and degrade rather than send data elsewhere, but we cannot audit their infrastructure for you.
Found something, or have a security or compliance question? Tell us through the Help screen inside Dotstrap, or the contact form on this site. We are a small team and would rather give you a direct, honest answer than a marketing one — and we would much rather hear about a vulnerability from you than from somebody else.
Take the address. Decide about the desk later.
It is free, it is yours permanently, and it cannot be changed afterwards.