Trust

Security at PromptImagica.

Protecting creators' work and buyers' data is table stakes. Here's how we do it.

Last updated: June 1, 2026

01Encryption everywhere

All traffic is encrypted in transit with TLS 1.3, and all data is encrypted at rest with AES-256. Payment card data never touches our infrastructure — it is handled end-to-end by PCI-DSS Level 1 certified processors.

02Account protection

Two-factor authentication is available on every account and required for creator payout changes. We monitor for credential-stuffing attacks, alert you on new-device logins, and support hardware security keys.

03Infrastructure and access

Production access follows least-privilege with short-lived credentials and full audit logging. Infrastructure is defined as code, changes ship through peer-reviewed pipelines, and backups are tested with quarterly restore drills.

04Responsible disclosure

Found a vulnerability? We want to hear about it. Email security@promptimagica.com with details and we'll acknowledge within 24 hours. We don't pursue legal action against good-faith research, and we credit reporters who wish to be named.

05Compliance

We align our controls with SOC 2 Type II and undergo annual third-party penetration testing. Reports are available to enterprise customers under NDA via sales@promptimagica.com.

Questions about this policy? Reach us at legal@promptimagica.com.