TRUST & SAFETY

Security at StackGrasp

How we protect accounts, payments, and platform data. Practices below are a draft summary — confirm exact certifications before publishing.

Account protection

Password hashing, optional 2-factor via the sign-in security code step, session monitoring, and device sign-out controls.

Data encryption

Data encrypted in transit (TLS) and at rest for account, payment, and Essence Credit records.

Payment security

Payments processed via PCI-compliant providers; StackGrasp does not store raw card numbers.

Course moderation

All submitted courses pass through the moderation queue before publishing, with reporting for post-publish issues.

Infrastructure

Access controls, audit logging, and monitoring across production systems.

Smart contracts

On-chain components (credentials, bounties) are treated as unaudited until formally reviewed — see the developer handoff notes.

Report a vulnerability

Found a security issue? Email security@stackgrasp.example (placeholder — confirm real contact before publishing). Please don't test against production without permission.