Security
PromptAng protects user data and payments with above-industry-standard care.
Last updated: June 30, 2026
End-to-End Encryption
All traffic is transmitted over TLS 1.3. Data is protected against eavesdropping.
bcrypt Password Storage
Passwords are hashed with 12-round bcrypt. Plain-text passwords are never stored.
Encrypted Database
The database is protected with server-level at-rest encryption. Backups are kept in a separate region.
Isolated Infrastructure
Each service is isolated at the container level and runs with least-privilege.
PCI-DSS Payments
Payments are processed via a secure payment provider (PCI-DSS Level 1). Card details never reach our servers.
Active Monitoring
Anomaly detection, rate-limiting and DDoS protection are always on.
Data Protection
User data is retained only for as long as necessary to provide the service. Under KVKK and GDPR, deletion or portability requests are fulfilled within 30 days. For details, see the Privacy Policy page.
Authentication
- Secure social login with Google OAuth 2.0
- HTTP-only, Secure, SameSite=Strict session cookies
- One-time, time-limited tokens for password reset
- Rate limiting against brute-force attacks
Responsible Disclosure
If you have found a security vulnerability, contact us before exploiting it: support@promptang.com
- Detail the vulnerability and share reproduction steps.
- Do not share the vulnerability with third parties before it is patched.
- Do not access, modify or delete user data.
- Response time: first reply within 72 hours.
A letter of appreciation and a hall of fame program are available for ethical researchers.
Incident Response
In the event of a security incident, we notify affected users within 72 hours and report to the relevant regulators within the legal timeframes.
Contact
Security questions: support@promptang.com
ANG Technologies Ltd · Company No: 17294566