Security
last updated 2026-07-27
Certifications
ColdShift holds no security certifications today. No SOC 2, no ISO 27001, no HIPAA, no PCI. Everything below is practice or intent, labeled as such.
This site, today
Served over TLS. No secrets or keys in the browser. No cookies, no third-party scripts, no analytics. The waitlist route stores nothing until a provider is wired and named.
The API, intended practice
Planned for the in-batch build: API keys hashed at rest, per-key region allowlists, no persistence of prompt or completion content beyond what routing and billing require, and audit logging of routing decisions. These are design intentions, not shipped guarantees. TODO(founder): revise this list as the build lands.
Reporting a vulnerability
If you find something, tell us and we will fix it. Contact: TODO(founder): security contact email. We will publish a disclosure policy with the product.