Security
What we do to protect the work you give us, and how to tell us if you find a hole in it.
How we think about it
People paste unpublished work into this tool. That is a real act of trust and the honest way to repay it is to describe what we actually do rather than to list reassuring words.
Citation Check is built and run by one person. This page says what is in place today, and says plainly what is not.
Your documents
- Everything travels over encrypted connections between your browser, our servers, and the providers we use.
- Documents are kept for as long as we need it to provide and improve the service and results for as long as we need them to provide and improve the service, and in your browser for as long as you keep them there, then removed.
- We may use the content you submit, and what you do with the results we show you, to operate, develop and improve our products and services. We do not sell your content and we do not publish it.
- Only the claim being checked and the pages we fetched to check it leave our servers, never the whole document.
- Data at rest is encrypted by our hosting and database providers as standard, and backups are theirs rather than ours.
How the service is built
- The website and application run on managed hosting with automatic certificate management and platform-level protection against volumetric attacks.
- Accounts and sign-in records live in a managed database with network restrictions and its own access controls.
- The verification engine runs behind an authenticated internal endpoint. It is not reachable from the public internet without a token.
- The engine runs with memory and process ceilings, so a malformed or hostile document cannot exhaust the machine.
- Uploaded files are parsed in a restricted path, and requests to internal network addresses are blocked, so a supplied URL cannot be used to reach our own infrastructure.
Access and accounts
- Sign-in uses Google or a one-time link sent to your email. We never store a password, so there is no password of yours for us to lose.
- Citation Check is run by one person, so production access is one account rather than a team with a process. Secrets live in the hosting provider’s encrypted environment, never in the codebase.
What we have not done yet
Being straight about the gaps is more useful than a page of assurances. As things stand we do not hold SOC 2, ISO 27001, or any comparable certification, we have not commissioned an external penetration test, and we do not offer a bug bounty. If any of those matter for your organisation, write to us and we will tell you where we are rather than guess.
Reporting a vulnerability
If you find a security problem, please tell us before you tell anyone else. Email info@citationcheck.ai with enough detail for us to reproduce it.
- We aim to acknowledge a report within three business days.
- Please give us a reasonable chance to fix it before publishing.
- Please do not access, change, or delete anyone else’s data while testing, and do not run attacks that degrade the service for other people.
- We will not pursue legal action over good-faith research that follows those lines.
If something goes wrong
If a breach affects your data we will tell you and the relevant regulator within the time the law requires, with what we know, what we are doing, and what you should do. We would rather send an early message that turns out to be minor than a late one that was not.