Security
How we protect your data
Encryption
Chatbot API keys and credentials are encrypted at rest using Fernet symmetric encryption. All traffic uses TLS in production.
Authentication
Passwords are hashed with bcrypt. Sessions use short-lived JWT access tokens and rotating refresh tokens. You can revoke sessions from Settings → Security.
Isolation
Each account's targets, scans, and reports are isolated. Admin access is restricted to authorized staff emails only.
Responsible disclosure
Found a vulnerability in AutoRedTeam? Email security@autoredteam.com. We appreciate responsible disclosure.