Security
How Midcrowd protects accounts and data, and what we ask of you.
Version 0.4.1-draft · Effective
Accounts and access
Sign-in is handled by a managed identity provider; Midcrowd never stores your password. A session is held in a cookie that JavaScript cannot read and that is only sent over HTTPS, and it can be revoked from your account settings on every device at once.
Access is default-deny and scoped per organization: a request carries the identity of the person making it and is checked against what that person's role permits on that specific website, on the server, on every read and every write.
Data in transit and at rest
Traffic is served over HTTPS and published sites are issued certificates automatically. Data is stored with a managed cloud provider and is encrypted at rest by that provider.
Pages are served with a Content-Security-Policy that admits only scripts carrying a per-request token, which is the control that stops injected script from executing even if it reaches a page.
Payment details
Midcrowd never sees or stores a card number. Card entry happens on our payment provider's own hosted pages, and we hold only the provider's identifiers and the last four digits it returns for display.
Records of privileged actions
Actions taken by Midcrowd staff on an account are written to an append-only audit record, so what was done, by whom and when can be answered rather than assumed.
What we need from you
- Use a password you do not use anywhere else, and keep your email account secure — it can reset everything else.
- Invite team members under their own accounts with the narrowest role that works, rather than sharing one login.
- Remove access as soon as someone stops needing it.
Reporting a vulnerability
If you believe you have found a security problem, write to us with enough detail to reproduce it and give us a reasonable chance to fix it before you publish anything. We do not currently run a paid bug-bounty programme, and we will not pursue anyone who reports a genuine issue in good faith without accessing other people's data.
What we do not claim
No system is perfectly secure, and Midcrowd holds no security certification or independent audit at this time. If we obtain one, this page will name it and date it. If a breach affects your data we will notify you without undue delay.
How to contact us
Questions about this document can be sent to midcrowd.ai@gmail.com. We aim to respond within 5 business days.
Midcrowd is the name this service trades under. The registered legal entity and address are to be confirmed before these terms are final.