Security
Your data is secure. Your privacy is protected. We never train on your conversations.
Code Security Assessment: Grade A (91/100) · Last reviewed August 2026
Your data never trains our AI
Pictor uses Anthropic's Claude API for AI coaching. Anthropic does not train on customer data. Your conversations remain completely private and are never used to improve AI models or shared with other customers.
Enterprise-grade security
All your data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3. We use Supabase (PostgreSQL) for secure data storage with enterprise-level security controls.
Every database table has Row-Level Security (RLS) policies ensuring users can only access their own data. We maintain 91 active RLS policies preventing any data leakage between users.
Our latest security assessment found zero critical vulnerabilities and confirmed our security practices meet OWASP ASVS Level 2 standards for applications handling sensitive data.
Secure authentication
We use industry-standard bcrypt password hashing (10 rounds) with HTTP-only secure cookies. Strong password requirements enforce uppercase, lowercase, numbers, and special characters.
Admin accounts have additional protection with automatic lockout after 5 failed login attempts for 30 minutes. All authentication attempts are logged for security monitoring.
Privacy and compliance
Pictor is fully compliant with GDPR, CCPA, and international privacy regulations. We're also PCI DSS compliant for payment processing (via Stripe) and SOC 2 ready.
You have full control over your data and can export or delete your account at any time. We practice data minimization and only collect what's necessary for the service.
No third-party data sharing
We never sell, rent, or share your data with third parties. Your coaching conversations, insights, and session data remain completely private.
Data retention and deletion
You own your data. When you delete your account, all your data is permanently removed from our systems. Deleted conversations are soft-deleted for 30 days to allow recovery, then permanently deleted.
We maintain regular encrypted backups for disaster recovery, but never use your data for any purpose other than providing the service to you.
Security practices
We maintain zero known vulnerabilities through regular security assessments and automated dependency monitoring. All code changes undergo security review before deployment.
Our infrastructure is hosted on SOC 2 certified platforms (Vercel and Supabase) with DDoS protection, automated security updates, and 24/7 monitoring.
Responsible disclosure
If you discover a security vulnerability, please report it responsibly to info@yourpaths.eu. We commit to responding within 48 hours.
Read our Privacy Policy for more details.