SECURITY
Security
Access control
Every Heritage Space is private by default. Access is granted by explicit membership or by an explicit Circle share — never inferred from a family relationship alone.
Authentication
Sign-in is handled through an authenticated session system with server-verified credentials. Deleting an account immediately revokes all of that account's active sessions.
Data in transit and at rest
Production traffic is served over HTTPS. Database credentials and application secrets are stored outside of source control and rotated when there's reason to believe they may have been exposed.
Face-matching data handling
Face-similarity signatures are stored per Heritage Space and are never used to search across spaces a person hasn't been added to. See the Privacy Policy for the full description of how face-matching assistance works.
Reporting a concern
If you believe you've found a security issue, please report it through the Contact page rather than a public forum, so it can be investigated before wider disclosure.