Specific claims, not reassuring adjectives.

Everything below is a property of how the service is built, not an aspiration. Where something is weaker than it sounds, we say so.

Sign-in

  • No passwords exist, so none can be reused, guessed or leaked.
  • Sign-in is a six-digit code, valid ten minutes, five attempts, rate limited by address and by caller.
  • Session tokens are stored as a SHA-256 hash. A copy of our database could not be replayed as a live session.
  • Codes are stored the same way and are never recoverable, by us or by anyone.

Separation between customers

  • Every query for site or client data is scoped to a tenant taken from the authenticated session or the request hostname, never from anything the browser sends.
  • That scoping lives in one place, so it cannot be forgotten in a new feature.
  • A suspended account is cut off before any content query runs.

Your clients’ work

  • Gallery media is in a separate store from public website media, reachable only through a handler that has checked a share token or a session.
  • While a gallery is withheld, the original file is refused by the server: a 403, not a hidden button.
  • Share links can carry a password and an expiry, both enforced server-side.
  • The watermark is a deterrent, not a control. It is drawn in the browser over a downscaled proof and a determined person can remove it. The release switch is what protects the work.

What runs on a published page

  • A content security policy restricts what any page may load or execute.
  • Customer content is rendered as text. Raw markup is never injected.
  • Uploads are identified by their actual file signature, not by what the browser claims, and video is accepted only into a gallery.
  • Folder paths from an upload are re-sanitised on the server before being stored.

Data handling

  • TLS everywhere; encryption at rest on the database and object storage.
  • Storage in the UK and EEA by default.
  • Records with no further purpose are deleted on a schedule, fault logs at 30 days and gallery activity at a year, rather than accumulating.
  • Device counts come from a one-way hash. The address itself is never stored.

What we do not have

  • No independent certification. We are not ISO 27001 or SOC 2 certified and will not imply otherwise.
  • No third-party penetration test yet. When there is one, it will be named here.
  • No public status page yet. Incidents are communicated by email to affected customers.

Reporting a vulnerability

Email security@noddable.com. Tell us what you found, how to reproduce it, and what you think the impact is. We acknowledge within two working days and tell you what we intend to do within ten.

We will not take legal action against you for research carried out in good faith under these rules, and we will credit you when we fix it unless you would rather we did not. We do not currently pay bounties.

Ground rules

  • Test against your own account and your own data only.
  • Do not access, modify or keep anybody else’s data. Stop as soon as you have proof.
  • No denial of service, no spam, no social engineering of our staff or customers.
  • Give us a reasonable chance to fix it before telling anyone else.

Security contacts are also published at /.well-known/security.txt. For how we handle personal data, see the privacy policy and the data processing agreement; for who else can see it, the sub-processor list.