Protecting your data and the systems you trust us to watch is part of what HopLogs does. This page summarises how we do it, and how to report a security problem.
How we protect data
- In transit: every connection to HopLogs uses TLS, and so do the connections between our own servers, databases and caches.
- At rest: the most sensitive fields (authentication secrets, tax IDs, addresses) are encrypted with AES-256-GCM using keys that stay on our servers; files such as attachments and exports are encrypted before they are stored. Database backups are encrypted.
- Payments: card details are handled entirely by Stripe's hosted pages. They never reach our servers.
- Access: operators sign in with mandatory two-factor authentication. Access is limited to what each role needs and reviewed every quarter.
- Accountability: every change anyone makes is recorded in a tamper-evident audit log, and reads of customer data by operators are logged.
- Software: dependencies are monitored for known vulnerabilities and updated continuously.
Reporting a vulnerability
If you think you have found a security problem in HopLogs, please email [contact email not configured] with the details and how to reproduce it. We will acknowledge your report within three business days and keep you updated until it is resolved.
While you investigate, please:
- only test against your own account and data;
- do not access, change or delete other customers' data;
- do not degrade the service for others (no denial-of-service testing, no automated scanning at high volume);
- give us reasonable time to fix the issue before telling anyone else.
We will not pursue legal action against people who report problems in good faith and follow these guidelines. Our machine-readable contact details are at /.well-known/security.txt.