Security & Responsible Use
CryptoSec Labs is built for lawful investigations. Here is how we protect your data and how we expect the platform to be used.
Encryption & Transport
- All traffic served over TLS 1.3 (HTTPS only)
- HSTS enforced with 1-year max-age
- Password hashing with bcrypt
- Session cookies: Secure + HttpOnly + SameSite=Lax
Evidence Handling
- Every artifact SHA-256 hashed on submission
- Chain-of-custody log records every view, copy and modification
- Timestamps on every action, immutable once recorded
- Exports preserve hashes and can be verified independently
Data Handling
- Only the minimum data needed to operate is stored
- No tracking cookies, no advertising networks
- Investigation targets are not shared with third parties
- Account data is deletable on request
- Audit logs retained up to 12 months for security
Responsible Use Policy
The Platform must only be used for lawful investigative purposes. Prohibited uses include:
- Stalking, harassment or doxxing of any person
- Unauthorized access to systems or accounts
- Bulk data collection for resale or competitive use
- Investigating minors
- Any use that violates applicable laws
Every tool call is logged with your account ID. Misuse results in immediate termination and may be reported to authorities.
Vulnerability Disclosure
If you discover a security issue in CryptoSec Labs, please report it responsibly to [email protected]. We will respond within 72 hours and credit any valid disclosures.
Contact
Security questions: [email protected]
Read our full Terms, Privacy Policy, and Refund Policy.