Security
Last updated: 4 August 2026
This page summarizes Dulty's current security controls and responsible disclosure channel.
Controls
- Workspace-scoped authorization and role checks.
- Hashed, expiring authentication tokens in secure HTTP-only cookies.
- Expiring candidate and report links with revocation controls.
- Authenticated, idempotent payment webhooks with order, currency, and exact-amount checks.
- Data minimization: assessment simulations do not update persistent fan or training skill profiles.
Responsible disclosure
Send security reports to support@dulty.app. Include reproduction steps and avoid accessing other users' data. We will acknowledge valid reports as soon as practical.
Shared responsibility
Customers should use unique credentials, remove former team members, share report links only with intended recipients, and avoid entering unnecessary personal data.