{✦} Stylumia Developers

Security at Stylumia

Security posture

The product corpus contains no PII — it is public retail listing data: prices, titles, images, and brands, published by retailers on their own storefronts. That one fact deletes most of a vendor security questionnaire before it starts, because there's no PII in the corpus to begin with:

  • No personal data to encrypt for a specific data subject.
  • No right-to-erasure workflow to build.
  • No PII retention clock to track.

What's actually in place

  • TLS everywhere. No unencrypted endpoint exists.
  • Server-side enforcement. Scope is re-checked on every request against the team's live entitlement — never trusted from a client, a cached token, or anything the caller asserts.
  • Keys stored as SHA-256. The plaintext exists only once, at creation, in your hands — see Credential security. We can't produce it again, including to ourselves.
  • Request logging with request_id. Every request is traceable server-side by the id it returns to you.
  • Audit log of key lifecycle events. Creation and revocation are recorded in the console with who did it and when.

Compliance

SOC 2 Type II is planned, with a stated intent but no committed date yet. Encryption in transit, least-privilege scope enforcement, and audit logging are in place today — no badges, no self-issued certifications, just what's actually true above.

Reporting a vulnerability

Email security@stylumia.com. Expect a response within 2 business days. If you're reporting a genuine security issue and stayed within the bounds of good-faith testing, we won't pursue action against you for the report — tell us what you found and how you found it.

View as markdown