Security policy
Eventually security is owned end-to-end by the technical co-founder, covering secure development, deployment, monitoring, vendor risk, and incident response. This article summarizes the commitments and contact points for partners and customers who need to review our security posture or report a concern.
How to report a security issue
Send vulnerability reports and security questions to [email protected]. We acknowledge receipt promptly and coordinate disclosure with you before any public announcement. We do not currently run a paid bug bounty program.
Incident response commitments
When a security incident is confirmed, we follow a five-step process:
Assess and classify — Determine severity and start an incident log.
Contain — Rotate or revoke affected credentials immediately.
Eradicate and recover — Remove the threat and restore service.
Notify — Inform affected customers and partners within our SLA window.
Post-incident review — Complete a review within 7 days.
Severity levels
Level | Definition |
|---|---|
P0 (critical) | Confirmed or suspected unauthorized access to customer or end-user data, credential compromise, or full service compromise. |
P1 (high) | Vulnerability exploitable against production with no evidence of exploitation; partial service compromise; sub-processor breach affecting our data. |
P2 (medium) | Vulnerability requiring unusual preconditions; incident contained to non-production systems. |
P3 (low) | Hardening gaps and best-practice findings. |
Notification SLAs
Customers: We notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach. The notice includes the nature of the breach, affected data categories and approximate counts, likely consequences, and the measures we have taken.
Partners: We notify partners without undue delay and no later than 72 hours after we become aware of a security incident affecting their data, systems, or integration. Updates are provided as the investigation progresses.
Regulators and data subjects: We notify these parties where required by law.
Endpoint and machine security
Company Macs use the macOS native security stack: XProtect, XProtect Remediator, Gatekeeper with app notarization, System Integrity Protection, FileVault disk encryption, automatic security updates, and enforced screen lock. We do not run a third-party antivirus or EDR agent.
Penetration testing and compliance
We do not currently have a staffed SOC.
Third-party penetration testing is planned, with a first engagement targeted within 12 months.
SOC 2 Type II is planned, with a target date to be determined.
Data retention related to security
Processed Squarespace webhook payloads are purged automatically after 30 days.
Application logs are kept in hot storage for up to 30 days.
Some API logs are currently retained longer while a purge job is planned.