Your brand data, protected by default.
You hand PopScript your brand, your product, and your team. Here's how we keep it safe — from the connection in your browser to the way we store, access, and eventually delete your data.
Posture, not marketing — described in plain language, without exposing anything that would help an attacker.
Encrypted, and locked down to who needs it.
Every layer — the connection, the storage, and the access — is closed by default and opened only where it has to be.
Encrypted in transit
All traffic to and from PopScript runs over HTTPS/TLS. Nothing you send or receive travels in the clear.
Encrypted at rest
Your brand, campaign, and roster data is stored on managed, access-controlled infrastructure with encryption at rest.
Least-privilege access
Public and low-trust reads return only an explicit, reviewed set of fields — never the whole record. Exports are sanitized so spreadsheet formulas can't execute.
Sessions built to limit the blast radius.
Signing in is the most sensitive thing you do. We treat it that way — hardened cookies, forgery protection, and a real logout.
Hardened session cookies
Sessions ride in HTTP-only cookies that page scripts can't read, scoped to our host and marked secure so they only travel over HTTPS. No long-lived access tokens are kept in the browser.
Forgery protection
Every state-changing request is protected against cross-site request forgery, so another site can't act on your account behind your back.
A real logout
Logging out revokes your session at the identity provider — not just in your browser — so the session can't be replayed after you leave.
Defense in depth, on every response.
Beyond the account, the platform itself is hardened — so a single mistake doesn't become a single point of failure.
Browser security headers
A strict content security policy, HTTP Strict Transport Security, and modern protective headers are enforced on every response.
Sanitized exports
Downloaded data is neutralized against formula injection, so an exported spreadsheet can't run code on the machine that opens it.
Monitored, with PII scrubbed
Errors are captured and monitored centrally so issues surface fast — with sensitive fields and credentials scrubbed before anything is logged.
Your data is yours.
We collect what we need to run the service, and nothing we do with it should surprise you.
Used only to run PopScript
We use your information to operate, secure, and improve the service — and to support you.
- We do not sell your personal information.
- Shared only with vetted providers who help run the service, under confidentiality obligations.
- Retained only while your account is active or as the law requires.
Your rights, on request
Depending on where you are, you can access, correct, delete, or export your personal information.
- Access and export a copy of your data.
- Correct or delete what we hold.
- See the full details in our Privacy Policy and Terms.
Found a vulnerability? Tell us.
We investigate every report and work in good faith with researchers who disclose responsibly. Please give us reasonable time to fix an issue before sharing it publicly.
security@popscript.comThe questions buyers ask us.
Is PopScript secure?+
How does PopScript protect my data?+
Does PopScript sell my personal information?+
How does PopScript keep my account and sessions safe?+
How do I report a security vulnerability?+
Trust, then get started.
Brief and certify every rep of your brand — on infrastructure built to keep your data safe.