Protecting creators' work and buyers' data is table stakes. Here's how we do it.
All traffic is encrypted in transit with TLS 1.3, and all data is encrypted at rest with AES-256. Payment card data never touches our infrastructure — it is handled end-to-end by PCI-DSS Level 1 certified processors.
Two-factor authentication is available on every account and required for creator payout changes. We monitor for credential-stuffing attacks, alert you on new-device logins, and support hardware security keys.
Production access follows least-privilege with short-lived credentials and full audit logging. Infrastructure is defined as code, changes ship through peer-reviewed pipelines, and backups are tested with quarterly restore drills.
Found a vulnerability? We want to hear about it. Email security@promptimagica.com with details and we'll acknowledge within 24 hours. We don't pursue legal action against good-faith research, and we credit reporters who wish to be named.
We align our controls with SOC 2 Type II and undergo annual third-party penetration testing. Reports are available to enterprise customers under NDA via sales@promptimagica.com.
Questions about this policy? Reach us at legal@promptimagica.com.