Trust & security

Your brand data, protected by default.

You hand PopScript your brand, your product, and your team. Here's how we keep it safe — from the connection in your browser to the way we store, access, and eventually delete your data.

Posture, not marketing — described in plain language, without exposing anything that would help an attacker.

Data protection

Encrypted, and locked down to who needs it.

Every layer — the connection, the storage, and the access — is closed by default and opened only where it has to be.

Encrypted in transit

All traffic to and from PopScript runs over HTTPS/TLS. Nothing you send or receive travels in the clear.

Encrypted at rest

Your brand, campaign, and roster data is stored on managed, access-controlled infrastructure with encryption at rest.

Least-privilege access

Public and low-trust reads return only an explicit, reviewed set of fields — never the whole record. Exports are sanitized so spreadsheet formulas can't execute.

Account & sessions

Sessions built to limit the blast radius.

Signing in is the most sensitive thing you do. We treat it that way — hardened cookies, forgery protection, and a real logout.

Hardened session cookies

Sessions ride in HTTP-only cookies that page scripts can't read, scoped to our host and marked secure so they only travel over HTTPS. No long-lived access tokens are kept in the browser.

Forgery protection

Every state-changing request is protected against cross-site request forgery, so another site can't act on your account behind your back.

A real logout

Logging out revokes your session at the identity provider — not just in your browser — so the session can't be replayed after you leave.

Platform hardening

Defense in depth, on every response.

Beyond the account, the platform itself is hardened — so a single mistake doesn't become a single point of failure.

Browser security headers

A strict content security policy, HTTP Strict Transport Security, and modern protective headers are enforced on every response.

Sanitized exports

Downloaded data is neutralized against formula injection, so an exported spreadsheet can't run code on the machine that opens it.

Monitored, with PII scrubbed

Errors are captured and monitored centrally so issues surface fast — with sensitive fields and credentials scrubbed before anything is logged.

Privacy

Your data is yours.

We collect what we need to run the service, and nothing we do with it should surprise you.

Used only to run PopScript

We use your information to operate, secure, and improve the service — and to support you.

  • We do not sell your personal information.
  • Shared only with vetted providers who help run the service, under confidentiality obligations.
  • Retained only while your account is active or as the law requires.

Your rights, on request

Depending on where you are, you can access, correct, delete, or export your personal information.

  • Access and export a copy of your data.
  • Correct or delete what we hold.
  • See the full details in our Privacy Policy and Terms.

Found a vulnerability? Tell us.

We investigate every report and work in good faith with researchers who disclose responsibly. Please give us reasonable time to fix an issue before sharing it publicly.

security@popscript.com
Security FAQ

The questions buyers ask us.

Is PopScript secure?+
Yes. All traffic runs over HTTPS with data encrypted in transit and at rest. Sessions use hardened, HTTP-only cookies with cross-site request forgery protection, public reads are limited to reviewed field allowlists, and strict browser security headers are enforced on every response.
How does PopScript protect my data?+
Your brand and campaign data is encrypted in transit over TLS and encrypted at rest on managed, access-controlled infrastructure. Access follows least privilege — public and low-trust reads return only explicit, reviewed fields, never the whole record — and exports are sanitized against spreadsheet-formula injection.
Does PopScript sell my personal information?+
No. PopScript does not sell your personal information. Data is used only to operate the service, and it is shared only with vetted providers who help run it, under confidentiality obligations.
How does PopScript keep my account and sessions safe?+
Sessions use hardened, HTTP-only cookies that scripts can't read, scoped and marked secure so they only travel over HTTPS, with cross-site request forgery protection on every state-changing request. Logging out revokes the session at the identity provider, not just in your browser.
How do I report a security vulnerability?+
Email security@popscript.com with the details. We investigate every report and work in good faith with researchers who disclose responsibly. Please give us reasonable time to fix an issue before disclosing it publicly.

Trust, then get started.

Brief and certify every rep of your brand — on infrastructure built to keep your data safe.