Policies
Security
What we do to keep accounts and job data safe, stated as it is, and how to tell us if you find a weakness. Strata Scope is in testing and has not been assessed against any security standard.
1How data is protected
- Sign-in. Each account has its own access code. The sign-in cookie is signed by the server, so it cannot be forged from an email address, and is marked so page scripts cannot read it. Repeated wrong codes are slowed down.
- Separation. Every job has its own record. A client account sees only the jobs a contractor has shared with that one account, cannot change any record that is not shared with it, and never sees anything priced.
- The AI key. Calls to the AI model are made by our server. The key never reaches a browser.
- The operator portal. Each operator sign-in gets its own token, which stops working on sign-out or after a week.
- Encryption in transit. This website is served over HTTPS only, and the sign-in cookies are marked to travel over HTTPS only on the hosted service. [TO CONFIRM: HTTPS-only on the tool's host once it is chosen]
- Testing our own changes. Changes that touch sign-in, sharing, uploads or stored files are attacked on an isolated copy before release, and each weakness found is recorded and fixed.
- Storage. [TO CONFIRM: hosting provider, region, encryption at rest and backups]
2Reporting a weakness
If you think you have found a security weakness in Strata Scope or this website, email mark@MTE-hq.co.uk with "Security" in the subject. Please include what you found, where, how to reproduce it, and what someone could do with it. The same address is published in our security.txt file at /.well-known/security.txt.
3Rules for testing
- Use only your own account, and data you are entitled to.
- Do not read, change or delete anyone else's data. If you reach some by accident, stop, and tell us what you saw.
- Do not degrade the service: no denial-of-service, load testing or spam.
- Do not use social engineering or physical attacks.
- Give us reasonable time to fix a problem before you tell anyone else about it.
[TO CONFIRM: solicitor, whether to promise not to take legal action against good-faith reports that follow these rules]
4What happens next
We will acknowledge your report within [TO CONFIRM: number of working days], keep you told of progress, and tell you when it is fixed. We do not run a paid bug bounty. With your permission, we will thank you by name when the fix is out.