Skip to main content

Security

Dracon takes the security of its products and customer data seriously. This page summarizes our security posture and our responsible-disclosure process.

Reporting a vulnerability

If you believe you've found a security issue in a Dracon product, please email security@dracon.uk with a reproduction and the affected version. We respond within five business days.

Encryption in transit

All Dracon services are reachable over HTTPS only. Authentication is handled through HttpOnly session cookies scoped to the relevant subdomain.

Encryption at rest

Persistent data (user accounts, billing, rankings cache) is stored in encrypted-at-rest managed databases.

Disclosure timeline

Confirmed vulnerabilities are disclosed after a fix has been deployed to all affected surfaces. We credit reporters with their consent.