Security at SecurityScore.me
We use HIBP breach data only. We store the minimum needed for breach checks and email alerts. This page summarizes our technical and operational security, how alerts work, and how to report a vulnerability.
1. Technical and Operational Security
We use industry-standard measures to protect your data and our systems:
- • Data in transit: TLS (HTTPS) for all connections.
- • Data at rest: encryption where provided by our infrastructure (e.g. database, hosting).
- • Access control: least-privilege access to production systems; secrets in environment variables, not in code.
- • Security headers: CSP, HSTS, X-Frame-Options, and related headers on the site.
2. How Breach Alerts Work
For monitored emails (paid plans), we run scheduled checks against Have I Been Pwned (HIBP) breach data. When new breaches are found for an email, we send an alert email to the address you configured. We do not read your inbox; we only query HIBP by email address and compare results with the previous run.
You can turn off alerts per email or globally via the unsubscribe link in each email or via your account settings.
3. Data Handling Summary
We store the minimum needed to provide breach checks and monitoring: account email (and optional name), monitored email addresses, timestamps (e.g. last check), alert preferences, and breach snapshot metadata (breach names, counts). We never store passwords. We do not read or access your inbox. For more detail, see our Privacy Policy.
4. Reporting a Vulnerability
If you believe you have found a security vulnerability in our service, please report it to us responsibly. Contact us at info@securityscore.me with a clear description and steps to reproduce. We will acknowledge receipt and work with you to understand and address the issue. We do not run a formal bug bounty program; we still appreciate responsible disclosure.
5. Contact
For security or privacy questions, contact us at info@securityscore.me.