Security Policy
Last Updated: June 3, 2026
1. Introduction
AIEasy is committed to protecting our users' data and the security of our platform. This security policy describes the practices and procedures we follow to maintain security.
Our security goals include:
- Protecting user data against unauthorized access.
- Preserving the integrity of our platform.
- Ensuring service availability.
- Maintaining user trust through transparent practices.
- Responding quickly to security incidents.
2. Reporting Security Issues
We welcome security researchers, ethical hackers, and technology enthusiasts to participate in our responsible disclosure program. We provide safe harbor for good-faith security testing and may offer rewards for vulnerability findings based on severity and potential impact.
If you discover a security vulnerability, please report it immediately to hello@aieasy.chat. Include:
- A detailed description of the vulnerability.
- Clear steps to reproduce the issue.
- Any relevant screenshots, logs, or proof-of-concept code.
- An assessment of the potential impact.
- Your contact information for follow-up.
We commit to:
- Acknowledge receipt within 1 business day.
- Work with you to validate and resolve the issue.
- Provide appropriate credit, if desired.
We value contributions from the security community to help keep AIEasy safe. All legitimate reports will be thoroughly investigated and handled with the appropriate urgency.
3. Our Security Practices
3.1. Data Protection
- All data is encrypted in transit using TLS (HTTPS).
- We collect only essential user information, following data minimization principles.
- Account and content data live in Supabase with Row Level Security (RLS) per user/workspace.
- Integration tokens (MCP, Google Docs) are stored encrypted on the server (AES-256-GCM).
- Error telemetry (Sentry) is sanitized to reduce PII in events.
- Account deletion cancels Stripe subscriptions, removes insights events, deletes the Auth user, and cleans Storage objects when possible.
3.2. Authentication
- Industry-standard authentication protocols.
- Support for multi-factor authentication.
- Secure session management.
3.3. Infrastructure
- Regular security audits and assessments.
- Ongoing security updates and patches.
- Monitoring for suspicious activity.
4. User Responsibilities
To help keep your account secure:
- Use secure authentication providers you trust.
- Keep your OAuth provider account secure with strong passwords and two-factor authentication.
- Never share access to your authorized AIEasy sessions.
- Report suspicious activity immediately.
Additional security recommendations:
- Review your account activity regularly.
- Sign out after use, especially on shared devices.
- Never click suspicious links, even if they appear to come from AIEasy.
- Keep your browser and devices up to date.
- Consider using a trusted password manager.
5. Policy Updates
We may update this Security Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page.
6. Contact
If you have any questions, concerns, or comments about this Security Policy or our security practices, please contact us at: hello@aieasy.chat