How we protect 50heads

These are the controls we run. No system is free of risk, so we also monitor for problems and welcome reports.

  • No passwords. Sign-in is by Apple, Google or a one-time code, so there is no 50heads password to steal or reuse.
  • Sessions use secure, HTTP-only cookies on the web. In the app, tokens are bound to the device, which is meant to stop a copied token working on another phone.
  • Sensitive actions (changing a payout method, tax details, creating API keys, closing an account) ask you to confirm it is you again.
  • API keys are stored only as hashes, shown once, scoped and capped. Requests that arrive with a browser origin header are refused, so keys are meant for servers and scripts; browsers connect with OAuth.
  • Money moves through regulated providers (Stripe, Wise, PayPal). We do not store full card or bank numbers.
  • Data is encrypted in transit and at rest. Staff access is limited by role, protected by multi-factor authentication and recorded in an audit log.
  • Uploads are checked for type and size, have image metadata (such as location) removed, and are screened for prohibited content before heads see them.

Reporting a vulnerability

Use the contact form. Our security.txt points to the same form.

Please include what you found, how to reproduce it and what an attacker could do with it. We'll acknowledge within two business days and keep you updated until it's fixed.

Our promise

If you act in good faith, report to us privately, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it, we won't take legal action against you, and we'll credit you here if you'd like.

In scope

50heads.com, api.50heads.com, mcp.50heads.com, auth.50heads.com and the 50heads apps.

Out of scope

Denial-of-service testing, social engineering of staff or heads, physical attacks, and findings in third-party services we use (report those to the provider).

Thanks

We'll list people who have helped keep 50heads safe here.