Effective Date: May 15, 2026 · Operator: Service Automations LLC (CapchaCloud)
CapchaCloud’s security program is designed to protect the confidentiality, integrity, and availability of Customer Data. This is not a certification. We continuously evolve our program. Questions: support@serviceautomations.ai (subject: “Security” or “Trust”).
Architecture and infrastructure
Edge-native architecture on a globally distributed network — no traditional VPC, no virtual machines, no exposed ports.
Multi-tenant isolation with per-tenant data isolation, per-tenant origin allowlists, and per-tenant API keys.
WORM-style storage for consent payloads, with cryptographic hash verification.
Stateless compute with no persistent local state — eliminates entire classes of server compromise risks.
Encryption
In transit: TLS 1.2 minimum, TLS 1.3 preferred, on all Service endpoints. HSTS enforced.
At rest: AES-256 (provider-managed) across primary data stores.
Webhook signatures: HMAC-SHA256 with rotating secrets.
API keys: Stored as hashed values; the plaintext key is shown only at issuance.
Post-quantum migration: CapchaChain blocks are co-signed with a NIST-standardized
post-quantum signature alongside the classical signature, plus a second post-quantum algorithm family on a
scheduled checkpoint for algorithmic diversity, and video-of-signing objects use a hybrid classical+post-quantum
key envelope. Algorithm-by-algorithm detail, quantum posture, and measured numbers are shared with auditors and
enterprise buyers under NDA on request (subject: “Crypto inventory”).
Access control
Multi-factor authentication required for all CapchaCloud administrative access.
Least-privilege principle for personnel and service-to-service credentials.
Audit logs for administrative operations.
Customer access via OAuth-only sign-in (no password storage); per-tenant API keys for programmatic access.
Dependency monitoring via GitHub Dependabot on every repository — automated security advisories and update pull requests, plus a CI-visible npm audit report on each build.
CLI-gated deploys with secrets isolated in the infrastructure provider’s encrypted secret store.
Monitoring and logging
Request, error, and security event logging at the edge.
Anomaly detection on authentication and capture endpoints.
Rate limiting at multiple layers.
Audit trail for billing events, webhook signature failures, tenant configuration changes, and Personal Data exports.
Vulnerability management
Dependency scanning via Dependabot (all repositories) with a CI-visible audit report on each build.
Responsible disclosure: contact support@serviceautomations.ai with subject “Security disclosure”. We commit to acknowledging credible reports promptly and to good-faith engagement with researchers acting under standard responsible-disclosure norms. See also security.txt and Vulnerability disclosure.
Coordinated disclosure before public release of any vulnerability affecting Customers where feasible.
Incident response
Documented playbook with severity classification.
24-hour triage window for credible reports.
Customer notification within 72 hours of confirmed Personal Data Breach (see DPA §9), and within 30 days of confirmed PHI Breach when a BAA is in effect (BAA §4.3).