Legal

Security Overview

Effective date: July 13, 2026

Last updated: July 13, 2026

This page is maintained by JenFryTalks LLC to answer common security and privacy questions about the Conflict Literacy Index. It describes controls currently in place. It is not a certification and does not replace an audit report.

Access and authentication

  • Password sign-in with hashed credentials; Google OAuth supported.
  • Session cookies with secure and HttpOnly flags.
  • Multi-factor authentication required for administrative access to production systems.
  • Least-privilege access; production access limited to personnel who need it.

Hosting and platform

  • Application and database hosted on a managed cloud platform in the United States.
  • Managed Postgres database with automated backups.
  • Row-level security policies at the database level, so each user only sees their own records and team admins only see their team's records.

Encryption

  • TLS 1.2+ for all connections between browsers and our servers.
  • AES-256 encryption at rest for the database and backups.

Data handling

  • Payments processed by Stripe. We do not store full card numbers.
  • Personal data limited to what the Service needs — see our Data Policy.
  • Subprocessors listed publicly at Subprocessors.

Application security

  • Input validation and parameterized queries to protect against injection.
  • CSRF protection on state-changing requests.
  • Secrets stored in a managed secrets store, not in source code.

Backups and continuity

  • Automated daily database backups with limited retention.
  • Documented recovery process.

Incident response

We investigate potential incidents on receipt. If we confirm a security incident affecting your data, we will notify affected customers and, where required, regulators within the timeframes required by law.

Responsible disclosure

If you believe you have found a security vulnerability, please email info@jenfrytalks.com with details and steps to reproduce. Please do not publicly disclose the issue until we have had a reasonable chance to investigate and remediate. We will acknowledge receipt within 5 business days.

Shared responsibility

We are responsible for the security of the Service. You are responsible for the security of your account: use a strong, unique password, keep your email account secure, and do not share credentials or seats.

Contact us

JenFryTalks LLC
Baltimore, Maryland, USA
info@jenfrytalks.com

This document is a plain-English template drafted by the product team. It is not legal advice. Please have qualified counsel review it before relying on it for regulated use (schools, EU/UK customers, enterprise contracts, or disputes).