Skip to content

Demo site. Fictional data; nothing is sent to anyone. Open the guided demo

Security

This page lists only controls that exist in the product today, then says plainly what is not yet in place. UltoPulto is pre-launch and has not been independently audited.

Last updated · Maintained by UltoPulto

01Architecture

Web application
Next.js, served over HTTPS. Public pages are rendered on the server and work without JavaScript.
API
FastAPI service over HTTPS. It is the only component that reads or writes personal data.
Database
Relational database with schema migrations. Postgres with pgvector in production; the public demo uses an ephemeral database that resets on deploy.
Request engine
Runs inside the API service on a schedule. Delivery is simulated unless switched on per verified contact.

02Browser-side face processing

  • Face detection and embedding run in your browser. The photo is read into memory on your device and is not uploaded.
  • The API has no endpoint that accepts an image.
  • A numeric face signature is accepted only together with an explicit biometric-consent flag; otherwise the request is rejected.
  • Signatures are never searched against other users’ uploads. There is no feature to look up a person by face.

03Authentication and access control

  • Sign-in is by one-time emailed link. No passwords exist to be stolen.
  • Link and session tokens are stored only as SHA-256 hashes. Links expire in 15 minutes and are single-use; sessions last 30 days.
  • Scan details are locked until the requester confirms a code sent to the email on the scan.
  • Scans and cases are scoped to the owning account; other accounts receive an error.
  • Staff functions require a staff flag set out of band. Staff actions on a case are written to its timeline with the staff member’s email.
  • Internal endpoints require a shared secret.

04Abuse prevention

  • Rate limits per network address, per email and per searched name, stored as hashes.
  • Sign-in link requests are rate limited per email and per network address.
  • Verification codes allow five attempts and expire after 30 minutes.

05Retention and deletion

  • You can delete any scan, including its face signature, from the results page.
  • You can delete your account and its scans.
  • A scheduled job removes face signatures older than 30 days for people who are not active subscribers.
  • Details are on the transparency page.

06Payments

Payments are handled by Stripe Checkout. Card details go to Stripe and never reach UltoPulto. Webhook messages from Stripe are verified by signature.

07Vendors

Vercel
Hosts the web application. Also provides aggregate, cookie-less page-view and loading-speed measurement on public pages; signed-in screens are excluded.
Railway
Hosts the API for the public demo.
Stripe
Payment processing. Not active on the demo.
Resend
Transactional email (sign-in links, codes, alerts). Not active on the demo.
Have I Been Pwned
Breach lookups. The email address being checked is sent to its API. Not active on the demo.

08Development practice

  • Automated tests cover the scan, verification, accounts, billing, the request engine, monitoring, rate limits and the operations console, and run on SQLite and Postgres.
  • Database changes go through reviewed migrations; a test fails if the schema and the migrations disagree.
  • Secrets are held in the hosting platform’s environment settings, not in the code.

09Not yet in place

  • Independent security audit and penetration test.
  • Field-level encryption of face signatures and case data at rest, beyond the hosting provider’s storage encryption.
  • Session cookies restricted from scripts; today the session token is held in the browser’s local storage.
  • Object storage with access controls for evidence screenshots.
  • A formal incident response plan, SOC 2 report or bug bounty.

10Reporting a vulnerability

A monitored security address will be published here before launch. Until then, please do not test against real personal data: the public site is a demo with fictional data.