Trust Center

Security at DrutoScan

We'd rather show you exactly what's implemented and what's still on the roadmap than make a blanket security claim.

Today

What's in place now

Encrypted transport

All traffic to drutoscan.com is served over TLS/SSL.

No third-party passwords

DrutoScan never asks for or stores your Facebook, Instagram, YouTube, or TikTok password. Connections use official OAuth/API authentication only.

Hashed passwords

Dashboard account passwords are stored hashed, never in plain text.

Roadmap

What's planned

Part of this rebuild's security hardening pass, ahead of any production launch of the premium dashboard.

Planned

Multi-factor authentication

Planned

httpOnly session cookies + CSRF protection

Planned

Security response headers (CSP, HSTS, etc.)

Planned

Role-based access control & audit logs

Planned

Encrypted storage for connected-account tokens

Planned

Rate limiting on authentication endpoints

Planned

Malware scanning on uploaded evidence files

Planned

Automatic session expiration

Responsible disclosure

If you believe you've found a security issue affecting DrutoScan, please email support@drutoscan.com with details and steps to reproduce. Please don't publicly disclose an issue before we've had a reasonable chance to address it. We don't currently run a paid bug bounty program.

No guarantee of absolute security. No online platform can promise it will never be compromised. We aim to follow reasonable, industry-standard practices and to be transparent when something changes.