Security First

How We Protect Your Data

Security and privacy are built into every aspect of SoulLytics. Here's how we keep your information safe.

Data Protection
Multiple layers of security protect your information

Encryption in Transit

All data transmitted using TLS 1.3 encryption

Encryption at Rest

Database and file storage use AES-256 encryption

Secure Headers

CSP, HSTS, and other security headers implemented

Regular Backups

Encrypted backups with 30-day retention

Access Control
Strict controls on who can access what data

Principle of Least Privilege

Systems only access data they absolutely need

Multi-Factor Authentication

All admin access requires 2FA

Audit Logging

All data access is logged and monitored

Regular Access Reviews

Quarterly reviews of all system permissions

Minimal Data Scopes
We only request the absolute minimum permissions necessary

Steam OAuth Permissions

When you connect your Steam account, we only request basic identity information.

What We Request:
  • • Steam ID (public identifier)
  • • Display name
  • • Avatar image
What We Don't Request:
  • • Email address
  • • Real name
  • • Friends list
  • • Game library
  • • Purchase history
Infrastructure Security
Enterprise-grade security for our hosting and operations

Hosting Security

  • • SOC 2 Type II compliant hosting
  • • DDoS protection and mitigation
  • • Network isolation and firewalls
  • • 24/7 security monitoring

Development Security

  • • Automated security scanning
  • • Dependency vulnerability checks
  • • Code review requirements
  • • Secure development lifecycle
Responsible Disclosure
Found a security issue? We want to hear from you.

Security Researchers Welcome

We believe in working with the security community to keep SoulLytics safe. If you discover a security vulnerability, please report it responsibly.

Reporting Process:
  1. Email security@soullytics.com with details
  2. Include steps to reproduce the issue
  3. Allow us 90 days to investigate and fix
  4. We'll credit you in our security acknowledgments
Please Don't:
  • • Access or modify user data
  • • Perform destructive testing
  • • Publicly disclose before we've had time to fix

Stay Informed

We'll notify users of any security updates or incidents that may affect their data.

Security Contact: security@soullytics.com