Security
How we protect your data — and how to tell us if you find a problem.
Last updated: 13 September 2026
Reporting a vulnerability
If you believe you have found a security issue in CreatifyHQ, please email
security@creatifyhq.com.
Please include enough detail for us to reproduce it — the endpoint or page, the steps you took, and what you observed.
- We will acknowledge your report within 3 business days.
- We will triage and respond with an assessment within 10 business days.
- We will tell you when the issue is fixed, and we are happy to credit you if you would like that.
Safe harbour
We welcome good-faith security research and will not pursue legal action against researchers who follow this policy. Please avoid privacy violations, destruction of data, and degradation of our service, and give us reasonable time to fix an issue before disclosing it publicly.
Out of scope: social engineering of our team, physical attacks, denial-of-service testing, and findings against our providers’ own infrastructure.
How we protect your data
- Encryption in transit. All traffic to CreatifyHQ uses TLS. Traffic between our internal services runs on an encrypted private network that is not exposed to the public internet.
- Encryption at rest. The access tokens for your connected social accounts are encrypted before they are stored. Passwords are hashed with bcrypt and are never stored in readable form.
- Payment data. Card details are handled entirely by Stripe. CreatifyHQ never sees or stores them.
- Separation between customers. Every request is bound to the account that made it, and — for customers using multiple workspaces — to the specific workspace in use. Access to a workspace is verified on every request, not assumed.
- Access control. Administrative access is limited, protected by multi-factor authentication, and reviewed on a quarterly schedule.
- Audit logging. Access-control decisions are recorded to a durable security log and reviewed regularly.
- Automated testing. A suite of cross-account isolation tests runs every day against the live service, and fails loudly if separation between customers ever regresses.
- Backups. The database is backed up and an automated restore is tested every week — because a backup that has never been restored is not a backup.
Our security programme
We maintain a documented information security programme covering access control, change management, incident response, business continuity and vendor management. We are working towards SOC 2 and ISO/IEC 27001 readiness. If you are evaluating CreatifyHQ for your organisation and need more detail, contact us and we will share what we can under NDA.
Related pages
Sub-processors · Privacy Policy · Data Processing · GDPR · security.txt