SECURITY
Security Policy
Last updated: September 15, 2026
1. Our commitment
Hirune treats the security of your data as a top priority and follows industry best practices to protect your information.
2. Measures in place
- All traffic is encrypted with SSL/TLS (HTTPS)
- Payment details are processed by PCI DSS-compliant Stripe; card numbers are never stored on Hirune servers
- Sign-in is delegated to WorkOS AuthKit; Hirune does not store passwords
- App distribution and entitlement records run on Cloudflare (Workers / D1 / R2)
- Hirune is hosted on Vercel and sets security headers such as X-Frame-Options
3. Playground caution
Anything you type into the playground is sent to the target app's server (for example, Traceboard). Do not enter secrets such as passwords or API keys.
4. Reporting a vulnerability
If you discover a security vulnerability, please report it to the address below. Include as much detail as possible: a description, reproduction steps, and the affected scope.
5. Incident response
If a security incident occurs, we will investigate promptly and notify affected users.