Security
LAST UPDATED 9 SEPTEMBER 2026
FROST IDENTITY
Every database query on the platform passes through FROST, our always-on security layer. Account isolation is enforced at the query level — not in application code — so one account can never read another's records.
IDENTITY
You can sign in with Google, with Apple, or with the username and PIN your administrator gave you, and single sign-on carries that session across every product. PINs are stored as scrypt hashes with a per-member salt and are never readable by us. Member identities are hashed deterministically and mirrored across services so there is one identity, everywhere.
ENCRYPTION
All traffic is encrypted in transit with TLS. Stored data is protected by account isolation, role stamping and audit trails rather than per-record encryption, and card details never reach us — they are held by Stripe.
MONITORING
HADES, our integrity scanner, continuously audits the codebase and data layer. File integrity is watchdog-sealed against a vault; any tampering raises an immediate alert.
INFRASTRUCTURE
The service runs on Google Cloud Platform in the United States. Assets are content-addressed and served through our CDN; application code is never publicly exposed. Stage and production are fully isolated — nothing reaches production except through the publish pipeline.
REPORTING
Found a vulnerability? Email LARRY@POSITIVEFEEDBACK.AI — we respond within 24 hours.