Security policy
Security
Dracon takes the security of its products and customer data seriously. This page
summarizes our security posture and our responsible-disclosure process.
Reporting a vulnerability
If you believe you've found a security issue in a Dracon product, please email security@dracon.uk with a reproduction and the affected
version. We respond within five business days. Machine-readable contact details
live at /.well-known/security.txt.
Report a vulnerability
Encryption in transit
All Dracon services are reachable over HTTPS only. Authentication is handled
through HttpOnly session cookies scoped to the relevant subdomain.
Encryption at rest
Persistent data (user accounts, billing, rankings cache) is stored in
encrypted-at-rest managed databases.
Disclosure timeline
Confirmed vulnerabilities are disclosed after a fix has been deployed to all
affected surfaces. We credit reporters with their consent.