Security
Dracon takes the security of its products and customer data seriously. This page summarizes our security posture and our responsible-disclosure process.
Reporting a vulnerability
If you believe you've found a security issue in a Dracon product, please email security@dracon.uk with a reproduction and the affected version. We respond within five business days.
Encryption in transit
All Dracon services are reachable over HTTPS only. Authentication is handled through HttpOnly session cookies scoped to the relevant subdomain.
Encryption at rest
Persistent data (user accounts, billing, rankings cache) is stored in encrypted-at-rest managed databases.
Disclosure timeline
Confirmed vulnerabilities are disclosed after a fix has been deployed to all affected surfaces. We credit reporters with their consent.