Security

Security & Privacy

Your data security is our top priority. Learn how we protect your information.

Security First

Crezt is built with security at its core. We employ industry-standard encryption, secure authentication, and regular security audits to ensure your data remains protected at all times.

AES-256-GCM Encryption

All OAuth tokens and sensitive data are encrypted using AES-256-GCM, one of the strongest encryption standards available. Your TikTok credentials are never stored in plain text.

HTTPS Everywhere

All data in transit is encrypted using TLS 1.3. We enforce HTTPS on all connections with HSTS headers to prevent downgrade attacks.

Secure OAuth

We use TikTok's official OAuth 2.0 flow for authentication. We never see or store your TikTok password - only secure access tokens that can be revoked at any time.

Password Hashing

Brand account passwords are hashed using bcrypt with secure work factors. Even in the unlikely event of a breach, passwords cannot be recovered.

Rate Limiting

Comprehensive rate limiting protects against brute force attacks and API abuse. Suspicious activity is automatically blocked and logged for review.

Security Headers

We implement comprehensive security headers including CSP, X-Frame-Options, X-Content-Type-Options, and strict Referrer-Policy to prevent common web attacks.

GDPR Compliance

We are committed to protecting your privacy and complying with GDPR and other data protection regulations:

  • Right to Access: Request a copy of all data we hold about you
  • Right to Deletion: Request deletion of your account and associated data
  • Data Portability: Export your data in a machine-readable format
  • Data Retention: Soft-deleted data is permanently removed after 90 days

Payment Security

All payments are processed through Stripe, a PCI-DSS Level 1 certified payment processor. We never store, process, or have access to your full credit card details. Escrow funds are held securely and distributed according to competition rules.

Report a Security Issue

If you discover a security vulnerability, please report it responsibly. We take all reports seriously and will respond promptly.

[email protected]