Trust

Security & Disclosure

The controls that protect Still Bureau accounts, sites, and private media — and how to reach us if you find a way around them.

Effective
Last updated

01How the platform is protected

Transport and storage

  • HTTPS is enforced everywhere, with HSTS, automatic certificate issuance and renewal, and a strict content security policy.
  • The database requires TLS, runs on a private network with no public route, and is backed up automatically with point-in-time recovery.
  • Media lives in a private, encrypted, versioned object store with public bucket access blocked. The application can serve web and thumbnail renditions when the site and gallery access rules permit it.

Access and authorization

  • Still Bureau does not store plaintext account passwords and cannot display or retrieve an original password. Locally managed credentials are stored as salted hashes.
  • Requests for non-public files are authorized server-side against the applicable dashboard session, gallery access state, or download control. Uploaded originals are available to visitors only through a gallery download route the photographer enabled. If commerce is later enabled, a for-sale original also requires a valid paid order.
  • Tenants are isolated by site. Owner-only areas — billing, domains, pricing, orders, and earnings — are unavailable to collaborators.
  • Owners can review and revoke active sessions, restrict sign-in by IP range, cap concurrent sessions, and set idle-session expiry.
  • Sensitive account actions are written to an audit trail visible to the account owner.

Operations

  • Paid checkout is not currently available. If it is enabled later, payment card fields are handled directly by Stripe rather than Still Bureau's servers.
  • Logs are configured to exclude request bodies, credentials, access tokens, message content, and private file URLs.
  • Background jobs require a separate shared secret. If payment or fulfillment webhooks are later enabled, their provider signatures are verified before processing.
  • Backups are restore-tested, and alerting covers database availability, message delivery failures, certificate expiry, and capacity. Payment-failure monitoring applies if paid payment paths are enabled.

02Reporting a vulnerability

If you believe you have found a security issue, tell us at hello@stillbureau.com with Security in the subject line. Please include:

  • a description of the issue and its impact;
  • the exact steps, requests, or proof-of-concept needed to reproduce it;
  • the affected URL, endpoint, or account role;
  • how you would like to be credited, if you would like credit.

We acknowledge reports within three business days, keep you updated while we investigate, and tell you when a fix ships. We do not currently run a paid bounty program.

03Safe harbor for good-faith research

We will not pursue legal action against you, or ask others to, for security research that follows these rules:

  • Use only accounts you own or have explicit permission to test.
  • Stop as soon as you confirm a vulnerability. Do not access, modify, download, or retain anyone else's data, and delete anything you obtained incidentally.
  • Do not degrade the Service. No denial of service, load testing, spam, brute forcing, or automated scanning that generates significant traffic.
  • Do not use social engineering, phishing, or physical attacks against our staff, customers, or vendors.
  • Give us a reasonable chance to fix the issue before disclosing it publicly, and coordinate the timing with us.
  • Comply with the law and with the Terms of Service in all other respects.

Testing that stays within these rules is authorized for the purposes of anti-hacking law, and the Acceptable Use Policy's prohibition on probing our systems does not apply to it.

04Out of scope

  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Missing hardening headers, cookie flags, or TLS configuration preferences with no working attack.
  • Content published by a photographer on their own site — report that under the Acceptable Use Policy instead.
  • Vulnerabilities in third-party services we do not control, such as Stripe or a browser push service. Report those to the vendor.
  • Issues that require a rooted device, a malicious browser extension, or physical access.
  • Rate-limiting or account-enumeration reports without a practical exploitation path.

05If something goes wrong

If a security incident affects personal information we hold, we investigate immediately, contain it, and notify affected customers and any regulator as the law requires and without undue delay. Where we act as a processor for a photographer, we notify that photographer so they can meet their own obligations to their clients.

Data-protection questions are answered in the Privacy Policy. Security questionnaires and data processing agreements: hello@stillbureau.com.