Security at DrutoScan
We'd rather show you exactly what's implemented and what's still on the roadmap than make a blanket security claim.
What's in place now
Encrypted transport
All traffic to drutoscan.com is served over TLS/SSL.
No third-party passwords
DrutoScan never asks for or stores your Facebook, Instagram, YouTube, or TikTok password. Connections use official OAuth/API authentication only.
Hashed passwords
Dashboard account passwords are stored hashed, never in plain text.
What's planned
Part of this rebuild's security hardening pass, ahead of any production launch of the premium dashboard.
Multi-factor authentication
httpOnly session cookies + CSRF protection
Security response headers (CSP, HSTS, etc.)
Role-based access control & audit logs
Encrypted storage for connected-account tokens
Rate limiting on authentication endpoints
Malware scanning on uploaded evidence files
Automatic session expiration
Responsible disclosure
If you believe you've found a security issue affecting DrutoScan, please email support@drutoscan.com with details and steps to reproduce. Please don't publicly disclose an issue before we've had a reasonable chance to address it. We don't currently run a paid bug bounty program.
No guarantee of absolute security. No online platform can promise it will never be compromised. We aim to follow reasonable, industry-standard practices and to be transparent when something changes.