Security Statement
Last updated: 1 August 2026 — DRAFT
Security approach
VOYNOT is designed around least privilege, deny-by-default database policies, account-level isolation and private storage. Secrets must remain on trusted server infrastructure and outside client bundles and source control.
Data and AI controls
Planned controls include encrypted transport, managed encryption at rest, row-level authorization, audit-sensitive operations, note-level AI exclusion, secure authentication flows and deletion/export tooling.
Reporting a vulnerability
Please report suspected vulnerabilities privately to security@voynot.com. Include the affected surface, reproduction steps and potential impact. Do not access other users’ data, degrade availability or publicly disclose an unresolved issue.
The production response timeline, safe-harbor language, supported versions and incident-notification procedure will be finalized before launch. This statement is not a guarantee that any system is free from risk.