Back to home

AuthUser Security

Responsible disclosure

We welcome good-faith security reports.

What to include in a report

  • Clear vulnerability description
  • Reproduction steps
  • Potential impact
  • Technical evidence (logs, screenshots, or PoC)

Commitments

  • Receipt acknowledgment within a reasonable timeframe
  • Investigation and risk-based prioritization
  • Coordinated disclosure before public release

Privacy architecture

AuthUser follows a privacy by design model:

  • Data minimization: we only process what is strictly required to verify legal age.
  • Purpose limitation: data is used for verification and technical fraud prevention.
  • Context separation: verification components are isolated from the public web experience.
  • In-transit protection: HTTPS/TLS for external communications.
  • Access control: role-based restrictions for internal systems.
  • Auditability: operational and security events are logged with limited retention.

Data retention policy

AuthUser applies limited and proportionate retention based on risk and legal obligations:

  • Operational and security data: temporarily retained for abuse detection, support, and compliance.
  • Application and audit logs: kept as needed for diagnostics and service integrity.
  • Business contact data: retained while there is an active relationship or legal basis.
  • Deletion or anonymization: once the processing purpose ends, data is deleted or anonymized.

If you need contract- or jurisdiction-specific retention windows, contact us at https://authuser.org/en/contacto.