Legal
Security Policy
Effective 2026-09-12.
1. Summary
We take the security of StratHub and the data you trust us with seriously. This policy explains how to report a security vulnerability, what you can expect from us in return, the legal safe harbor we extend to good-faith research, and the technical measures we use to protect the platform. For how we collect and handle personal data, see our Privacy Policy.
2. Reporting a vulnerability
If you believe you have found a security vulnerability in a system listed in our Scope below, please report it through our contact form. This is our official channel for security reports. To help us triage quickly, please include:
- the affected URL, endpoint, or extension component;
- a clear description of the issue and its potential impact;
- the steps required to reproduce it (a proof of concept, request/response pairs, or a short screen recording);
- any accounts or test data you used.
3. What you can expect from us
- Acknowledgement of your report within 3 business days.
- A triage assessment — whether we can reproduce it and our initial severity rating — within 10 business days.
- An honest status as we work toward a fix, and notice when it ships.
- Credit for your discovery in any public acknowledgement, if you would like it. StratHub does not currently operate a paid bug-bounty program, so reports are not eligible for monetary reward.
4. Scope
This policy applies to the digital assets owned and operated by StratHub:
- strathub.ai and its subdomains — the web platform and dashboard;
- the StratHub API served under
strathub.ai/api/*; - the StratHub browser extension (Chrome/Edge, Manifest V3).
5. Out of scope
The following are not covered by this policy. Do not test them under it:
- Stake.us / Stake.com and their infrastructure. StratHub is not operated by, affiliated with, or endorsed by Stake. Report issues in Stake’s own systems to Stake, not to us.
- Third-party providers we build on — including Supabase, Vercel, Stripe, and the AI providers (Anthropic, OpenAI, OpenRouter, DeepSeek, Groq). Report issues in their platforms through their own disclosure programs.
- Volumetric denial-of-service (DoS/DDoS), or any testing that degrades service for other users.
- Social engineering, phishing, or physical attacks against StratHub, its staff, or its users.
- Findings that require an already-compromised account, a rooted/jailbroken device, or a machine-in-the-middle position you control.
- Reports from automated scanners without a demonstrated, exploitable impact; missing best-practice headers or configuration with no proven security consequence.
- The proprietary strategy content itself. Attempting to exfiltrate, redistribute, or defeat the licensing/entitlement controls on strategy definitions is not authorized security research and is not covered by the safe harbor below.
6. Rules for researchers
To keep your research within this policy and its safe harbor, you agree to:
- test only against in-scope systems;
- limit the data you access to the minimum needed to demonstrate the issue, and stop immediately if you encounter another user’s personal data — then tell us;
- avoid violating others’ privacy, disrupting our systems, or destroying or corrupting data;
- not use the vulnerability to pivot further, maintain persistence, or access data beyond the proof of concept;
- use only the official channel above to discuss the issue, and not engage in extortion;
- give us a reasonable amount of time to resolve the issue before disclosing it publicly (see §8).
7. Safe harbor
When you conduct security research in good faith and in accordance with this policy, we consider that research to be:
- Authorized under applicable anti-hacking laws (such as the U.S. Computer Fraud and Abuse Act), and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;
- Authorized under applicable anti-circumvention laws (such as the DMCA), and we will not bring a claim against you for circumventing technical controls, to the extent you do so to conduct research permitted here;
- Exempt from restrictions in our Terms of Service that would otherwise interfere with good-faith security research, for the limited purpose and duration of that research.
If at any point you are uncertain whether your research is consistent with this policy, contact us through our contact form before going further, and we will clarify.
This safe harbor applies only to legal claims under StratHub’s control. It does not bind independent third parties, and it does not authorize action against the out-of-scope systems in §5 — including Stake and our service providers, who have not agreed to these terms. You remain responsible for complying with all applicable laws.
8. Coordinated disclosure
We practice coordinated disclosure. We ask that you give us a reasonable opportunity to remediate before publishing details of a vulnerability — normally 90 days from your report, or sooner once a fix has shipped and we agree. If a fix will take longer, we will tell you and work out a timeline together. We are happy to coordinate a joint disclosure and to credit you.
9. How we protect the platform
- In transit: TLS 1.3, with HSTS (including preload) enforced on every response.
- At rest: AES-256, managed by our database and hosting providers (Supabase, Vercel).
- Credentials: account passwords are hashed with bcrypt using per-account salts; we never store them in plaintext, and we never receive your Stake password.
- Sessions: cookies are HTTP-only, Secure, and SameSite=Lax, signed with an HS256 JWT and a server-side secret.
- Access control: row-level security policies isolate each user’s data at the database layer; staff access is role-based.
- Abuse controls: authentication endpoints are rate-limited per IP and account, and repeated failed administrator sign-ins trigger a temporary lockout.
- Browser hardening: a strict Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, and a restrictive Permissions-Policy are sent on every page.
- Audit trail: staff administrative actions are recorded in an append-only audit log secured with a SHA-256 hash chain.
- Payments: when card payments are enabled they are processed by Stripe; we do not store card numbers.
See our Privacy Policy for how these measures apply to your personal data, and for data retention and your rights.
10. Data incident notification
If we determine that a security incident has affected your personal data, we will notify affected users and any applicable regulators as required by law (for example, within the timelines set by the GDPR and applicable U.S. state breach-notification statutes), and we will describe what happened and the steps we are taking.
11. security.txt
Our machine-readable contact information is published, per RFC 9116, at /.well-known/security.txt.
12. Changes
We may update this policy. Material changes will be announced on the site before they take effect. The “Effective” date above reflects the current version.
13. Contact
Security reports: submit through our contact form.