Legal & Compliance

Security policy

Eventually security is owned end-to-end by the technical co-founder, covering secure development, deployment, monitoring, vendor risk, and incident response. This article summarizes the commitments and contact points for partners and customers who need to review our security posture or report a concern.

How to report a security issue

Send vulnerability reports and security questions to [email protected]. We acknowledge receipt promptly and coordinate disclosure with you before any public announcement. We do not currently run a paid bug bounty program.

Incident response commitments

When a security incident is confirmed, we follow a five-step process:

  1. Assess and classify — Determine severity and start an incident log.

  2. Contain — Rotate or revoke affected credentials immediately.

  3. Eradicate and recover — Remove the threat and restore service.

  4. Notify — Inform affected customers and partners within our SLA window.

  5. Post-incident review — Complete a review within 7 days.

Severity levels

Level

Definition

P0 (critical)

Confirmed or suspected unauthorized access to customer or end-user data, credential compromise, or full service compromise.

P1 (high)

Vulnerability exploitable against production with no evidence of exploitation; partial service compromise; sub-processor breach affecting our data.

P2 (medium)

Vulnerability requiring unusual preconditions; incident contained to non-production systems.

P3 (low)

Hardening gaps and best-practice findings.

Notification SLAs

  • Customers: We notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach. The notice includes the nature of the breach, affected data categories and approximate counts, likely consequences, and the measures we have taken.

  • Partners: We notify partners without undue delay and no later than 72 hours after we become aware of a security incident affecting their data, systems, or integration. Updates are provided as the investigation progresses.

  • Regulators and data subjects: We notify these parties where required by law.

Endpoint and machine security

Company Macs use the macOS native security stack: XProtect, XProtect Remediator, Gatekeeper with app notarization, System Integrity Protection, FileVault disk encryption, automatic security updates, and enforced screen lock. We do not run a third-party antivirus or EDR agent.

Penetration testing and compliance

  • We do not currently have a staffed SOC.

  • Third-party penetration testing is planned, with a first engagement targeted within 12 months.

  • SOC 2 Type II is planned, with a target date to be determined.

  • Processed Squarespace webhook payloads are purged automatically after 30 days.

  • Application logs are kept in hot storage for up to 30 days.

  • Some API logs are currently retained longer while a purge job is planned.

Was this helpful?