Security
How we protect your brand data
Brandsscanner AI is built with the security posture small businesses need — without the enterprise paperwork.
Encryption
- • TLS 1.2/1.3 for all traffic. HSTS preload.
- • AES-256 at rest for uploads and generated content.
- • Passwords hashed with bcrypt; secrets stored outside source control.
Access controls
- • Optional 2FA (TOTP).
- • Per-user role: admin, member, viewer.
- • Audit log of state-changing actions.
Data
- • GDPR + LGPD compliant — export/delete your data from the dashboard.
- • We do not train third-party models on your content.
- • Daily off-site DB backups, 14-day retention.
Disclosure
Found a vulnerability? Email security@brandsscanner.com. We respond within 48 hours and credit responsible disclosure in our security advisories.