Trust

Security and Responsible Use

A summary of the private pilot’s current safeguards and reporting process.

Updated: August 4, 2026

Current safeguards

  • HTTPS for the public site and pilot application
  • Invitation-only shared access-code authentication
  • Secure, HTTP-only session cookies and CSRF protections
  • Rate limiting for failed login attempts
  • Content-type validation, file-size limits, and normalized upload handling
  • Standard browser security headers and restricted framing
  • Short-lived customer job storage with automatic deletion configured within 72 hours
  • One application instance and controlled job concurrency during the pilot

Responsible disclosure

Send suspected vulnerabilities to support@understanddecide.com. Include the affected URL, steps to reproduce, expected and actual behavior, and any screenshots that do not expose another person’s documents or personal information.

Do not access, modify, retain, or share data belonging to another user. Do not disrupt the service, perform denial-of-service testing, use automated high-volume scanning, or publicly disclose a vulnerability before we have had a reasonable opportunity to review it.

No bug bounty

The private pilot does not currently operate a paid bug-bounty program. A good-faith report is still appreciated.

Security limits

No internet service is perfectly secure. The safeguards listed here describe the current pilot configuration and are not a warranty or certification.