Security

This page describes the security of Cravim as it is currently built. It is deliberately specific. A security page that lists reassuring adjectives without naming a single mechanism is worth nothing to the person reading it.

Accounts and passwords

Your password is stored as a bcrypt hash and never in a form we can reverse. Nobody at C2Z LABS LLC can look up your password, and a copy of the database does not contain one. If you ask us for it, we will tell you the same thing — not because of policy, but because it does not exist.

Sessions are held in a signed, HTTP-only cookie, which means page scripts cannot read it. Logging out invalidates it.

Connected social accounts

Connecting Instagram, Facebook, Google Business, LinkedIn, TikTok or YouTube goes through that network’s own OAuth screen, on the network’s own domain. You type your password into their page, not ours. We never see it, and we never ask for it. What we receive back is an access token scoped to the specific permissions you granted — usually “read your pages” and “publish to them” — and you can revoke it from inside the network at any time without involving us.

Those tokens are stored encrypted. If a token expires or is revoked, publishing stops and you are told; it does not silently keep trying or silently pretend to have succeeded.

The approval gate

Every generated item lands in an approvals queue. Nothing is sent to a live account until a human approves that specific item. This is a security property as much as a product one: the worst case for an automated marketing tool is posting something wrong to a real business’s real profile, and the gate is what makes that impossible rather than unlikely.

Infrastructure

Cravim runs on Amazon Web Services in the United States. Traffic to the application is served over HTTPS only. The database is not reachable from the public internet. Uploaded and generated media is stored in object storage under unguessable keys.

Your content and AI providers

Generating anything means sending your brief, and sometimes your uploaded media, to the AI providers we use. Those providers are contractually barred from training their models on it. We do not train any model of our own on your content either. The providers your data actually passes through are named in the Privacy Policy — that list is meant to be accurate rather than generic, so it is kept there where it belongs.

Getting your data out, or deleted

Export and deletion are both self-service, from Settings → Your data. The export is a single file. Deletion is immediate and permanent — we would rather you be able to leave without asking permission.

What we do not claim

We do not hold SOC 2, ISO 27001 or any equivalent certification, and we have not had a third-party penetration test. If your procurement process requires either, tell us what you need and we will give you a straight answer about whether we have it rather than a maybe.

Reporting a vulnerability

Email hello@cravim.ai with “Security” in the subject. Include enough detail to reproduce it. We look at security reports the day they arrive and will confirm receipt.

We will not pursue legal action against anyone who reports a genuine issue in good faith, gives us a reasonable chance to fix it before going public, and does not access, alter or destroy other people’s data while investigating. We do not currently run a paid bug bounty.