Back to Portal

Security Policy

Effective Date: August 11, 2026

Our Commitment to Security

BespokeDB is designed with a security-first approach. We leverage Google Cloud infrastructure to ensure that your data is handled with enterprise-grade security protocols.

Infrastructure Security

  • Encryption in Transit: All communications between your client (browser or Emby server) and our API are encrypted using TLS 1.2 or higher (HTTPS). We do not support insecure HTTP connections.
  • Encryption at Rest: All data stored in our database (Google Cloud Firestore) is encrypted at rest by default using Google-managed encryption keys.
  • Authentication: We use Google Firebase Identity Platform for authentication. We never handle, store, or have access to your passwords.
  • API Secret Security: Your API secret is generated securely and immediately hashed (salted `scrypt`) before being stored in our database. We never store or display your API secret in plaintext, following industry best practices for zero-knowledge credential storage.
  • API Transport Security: API endpoints are secured using JSON Web Tokens (JWT) signed with HMAC-SHA256. API calls without a valid Bearer token are strictly rejected.

Vulnerability Reporting (Bug Bounty)

We welcome and encourage security researchers to responsibly disclose any potential vulnerabilities they discover in our API, dashboard, or infrastructure. We adhere to the standard security.txt RFC 9116 guidelines.

Please note that BespokeDB operates as a SaaS product. While we take security extremely seriously, we do not currently offer monetary payouts or maintain a public hall of fame for vulnerability reports. We do, however, deeply appreciate your efforts in keeping our service and users secure.

  • Out of Scope: Volumetric DDoS attacks, social engineering, physical security, or bugs in the Google Firebase infrastructure itself.
  • Reporting: Please email your findings, along with steps to reproduce, to security@bespokedb.cloud. We aim to acknowledge reports within 72 hours.

Contact Us

If you have any questions or concerns regarding our security practices, or if you need to report a potential security issue, please contact us at: security@bespokedb.cloud