Legal

Security & Responsible Disclosure

Last updated: 4 September 2026

How Memberra protects data

Memberra uses encrypted HTTPS connections, tenant-level access controls, role and permission checks, protected secret storage, audit trails, request limits, signed webhook validation, restricted administrative functions, optional multi-factor authentication, backups and monitored production health. Sensitive connected-service credentials are not intentionally exposed to other Operators or their customers.

Payments stay with payment providers

Stripe or PayPal securely collects and processes payment credentials when that provider is selected. Memberra does not store full card numbers, card security codes, online-banking credentials or PayPal passwords. Memberra receives limited payment status, amount, currency and transaction/account references so it can reconcile billing and run the automation requested by the Operator. End-customer funds are processed by the selected provider and are not held by Memberra.

Privacy by default

Memberra limits collection to information needed to provide a selected feature, protect accounts, support users, or meet a stated legal obligation. New media-server connections default to masked network identifiers; more detailed watch analytics are optional and controlled by the Operator. Authentication security records and temporary enrichment caches have automatic retention limits.

Reporting

Send suspected vulnerabilities privately to [email protected] with reproduction steps, affected URLs and impact. Do not include unnecessary personal data. We will acknowledge and triage reports as resources permit; no bounty or payment is promised.

Good-faith research

Use test accounts and the minimum activity needed to demonstrate a problem. Do not access another person's data, degrade service, persist access, use social engineering, test third-party providers, upload malware, publish before remediation, or demand payment. Stop immediately if personal data or secrets are exposed and report what occurred.

Safe handling

Where research is lawful, follows this policy and is reported promptly, Memberra does not intend to pursue action solely for that good-faith testing. This statement is not permission from third parties, a waiver of applicable law or a promise concerning law-enforcement decisions.

Security limitations

Memberra uses proportionate safeguards but no online service is completely secure. Operators remain responsible for connected servers, credentials, permissions, backups and incident response within their control.