Security

Your data is safe.

We take security seriously. Here's exactly what we do to protect it.

What we do

Encryption everywhere

All data is encrypted in transit using TLS 1.3. Data at rest is encrypted using AES-256.

Rate limiting

All API endpoints are rate-limited to prevent abuse and brute-force attacks.

European servers

All data is stored on servers within the European Economic Area. No data leaves Europe.

Input validation

All user input is validated and sanitized server-side. SQL injection and XSS protections are built in.

What we don't do
  • We never sell your data to any third party
  • We don't use tracking pixels or fingerprinting
  • We don't store passwords in plain text (bcrypt hashing)
  • We don't share data with advertisers
  • We don't use third-party analytics that track individuals

Found a vulnerability?

We take security reports seriously. If you've discovered a potential security issue, please contact us responsibly before disclosing it publicly.

We commit to acknowledging your report within 48 hours and working with you to understand and fix the issue as quickly as possible.

Please encrypt sensitive reports using our PGP key (available on request).

A note on alpha security

Wiiseto is currently in alpha. While we implement strong security practices from day one, we recommend not storing highly sensitive production data on the platform during this phase. Security posture will continue to improve as we mature toward general availability.