Security

Last updated: 7 July 2026

Security is central to HasMyBrandChanged. Customers may upload confidential brand assets, internal documents, presentations and marketing material. We design the Service to protect this information and keep each customer workspace isolated.

Contact us about security at support@hasmybrandchanged.com.

1. Security approach

HasMyBrandChanged is built around the following security principles:

  • Tenant isolation
  • Least privilege access
  • Private file storage
  • Secure authentication
  • Server-side validation
  • Configurable file retention
  • Auditability
  • No use of customer files for AI training

2. Multi-tenant isolation

HasMyBrandChanged is a multi-tenant SaaS application. Each workspace belongs to a company or organisation, and customer data is scoped to the customer workspace. Users should only access data for workspaces where they are authorised members. We use database-level access controls and application-level checks to reduce the risk of cross-tenant access.

3. Authentication

Authentication is handled through secure authentication providers. Supported authentication may include email and password, and Google sign in. Passwords are not stored in plain text by HasMyBrandChanged.

4. Authorisation and roles

Workspace permissions are role-based. Typical roles include Owner, Admin and Member. Owners and admins control sensitive actions such as editing Brand Blueprints, managing users, managing subscriptions and changing retention settings.

5. File storage

Uploaded files are stored in private storage and are not publicly accessible. Temporary signed URLs may be used where access is required for processing or user review. Original uploaded files are retained according to workspace retention settings.

6. File retention

Retention is configurable. The default retention period is 90 days unless changed. Users may delete review assets where supported. Review metadata and findings may remain for review history after original files are deleted.

7. AI processing

Uploaded assets may be processed by AI systems to generate review findings. Customer files are not used by HasMyBrandChanged to train AI models. Where commercial AI APIs are used, we rely on provider terms that state API inputs and outputs are not used to train their general models unless separately opted in.

8. Encryption

Data is encrypted in transit using secure connections. Files are stored in private infrastructure with access controls. Secrets and API keys are stored outside the client application.

9. Audit logging

We may log important security and account events, including:

  • Sign in and failed sign in
  • Brand Blueprint changes
  • File uploads
  • Review creation
  • Team changes
  • Subscription changes
  • Retention setting changes

Logs are used for security, debugging and abuse prevention.

10. What we do not do

We do not:

  • Sell customer files
  • Use customer files for advertising
  • Use customer files to train our own AI models
  • Make customer uploads public
  • Intentionally expose one customer’s data to another

11. Responsible disclosure

If you discover a security vulnerability, contact us immediately at support@hasmybrandchanged.com. Please include a description of the issue, steps to reproduce, any affected URLs or accounts, and your contact details.

Do not access, modify or delete data that does not belong to you. Do not publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate and respond.

12. Security limitations

No system is perfectly secure. We continuously improve the Service, but we cannot guarantee that unauthorised access, data loss or security incidents will never occur.

13. Enterprise security

Enterprise customers may request additional security information, including data retention options, sub-processor information, security questionnaires, audit logs, SSO roadmap and custom agreements. Contact support@hasmybrandchanged.com.