Security

How Detris protects your data

Data Encryption

Data is encrypted in transit and at rest. API keys are stored as hashes; connected-service credentials are encrypted.

Authentication

  • Hashed passwords
  • Time-limited access tokens
  • Refresh token rotation with automatic revocation on reuse
  • Google OAuth 2.0 single sign-on
  • Rate-limited login and password reset endpoints

Access Control

Owner, Editor, and Viewer roles control access to each list. Permissions are enforced server-side.

Infrastructure

  • DDoS protection and authentication bot filtering
  • Firewall-protected infrastructure
  • Automated intrusion detection
  • No customer data stored on local developer machines

Monitoring

Alerts monitor unusual authentication, errors, and API activity. Rate limits help prevent abuse.

Vulnerability Management

Automated dependency scanning identifies known vulnerabilities. Critical patches are applied within 48 hours of disclosure.

Data Retention

  • API usage logs auto-expire after 90 days
  • Audit logs retained for 1 year, then automatically purged
  • You can export your data at any time in CSV or JSON format

Account Control

Export lists as CSV or JSON. Delete your account in Settings to initiate removal of your lists, templates, chats, and usage records.

Contact

To report a vulnerability or ask a security question, email [email protected].