How we protect 50heads

  • No passwords. Sign-in is by Apple, Google or a one-time code, so there's no password to steal or reuse.
  • Sessions use secure, HTTP-only cookies on the web and device-bound keys in the app: a copied token doesn't work on another phone.
  • Sensitive actions (changing a payout method, tax details, creating API keys, closing an account) ask you to confirm it's you again.
  • API keys are stored only as hashes, shown once, scoped, capped and refused from browsers.
  • Money moves only through regulated providers (Stripe, Wise, PayPal). We never store full card or bank numbers.
  • Data is encrypted in transit and at rest, access is limited by role with multi-factor authentication, and every administrative action is logged.
  • Uploads are size-checked, re-encoded and scanned before anyone sees them.

Reporting a vulnerability

Email security@50heads.com. Our security.txt has the same details.

Please include what you found, how to reproduce it and what an attacker could do with it. We'll acknowledge within two business days and keep you updated until it's fixed.

Our promise

If you act in good faith, report to us privately, avoid privacy violations and service disruption, and give us reasonable time to fix the issue before disclosing it, we won't take legal action against you, and we'll credit you here if you'd like.

In scope

50heads.com, api.50heads.com, mcp.50heads.com, auth.50heads.com and the 50heads apps.

Out of scope

Denial-of-service testing, social engineering of staff or heads, physical attacks, and findings in third-party services we use (report those to the provider).

Thanks

We'll list people who have helped keep 50heads safe here.